Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-56843: Plesk XML-RPC API: Low-Privileged Users Can Access Other Domains
CVE-2026-56843
CVE-2026-56843
Summary
A security issue in Plesk's XML-RPC API allows low-privileged users to see details of domains they don't own. This could lead to unauthorized access to sensitive information, such as FTP credentials, which might be used to take control of other users' accounts. To fix this, update Plesk to version 18.0.78.4 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | plesk | < 18.0.78.4 |
Original title
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only fo...
Original description
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.
nvd CVSS3.1
9.9
Vulnerability type
CWE-522
Insufficiently Protected Credentials
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026