CVE-2026-48614
Deferred Deferred - Pending Action

Improper Authorization in Plesk XML API Leading to Privilege Escalation

Vulnerability report for CVE-2026-48614, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-06

Last updated on: 2026-07-06

Assigner: HackerOne

Description

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-06
Last Modified
2026-07-06
Generated
2026-07-27
AI Q&A
2026-07-06
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
plesk xml_api to 18.0.30 (exc)
plesk xml_api From 18.0.0 (inc) to 18.0.30 (exc)
plesk onyx 17.x

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-48614 is an improper authorization vulnerability in the Plesk XML API that allows an authenticated user to inject arbitrary configuration directives.

This injection leads to arbitrary file write operations as the root user and results in full privilege escalation on the underlying server.

The vulnerability affects Plesk XML API versions below 18.0.30 and was responsibly disclosed by Georgii Shutiaev.

Detection Guidance

To detect if your system is vulnerable to CVE-2026-48614, you should first verify the version of the Plesk XML API installed. Versions below 18.0.30 are affected by this vulnerability.

There is no specific command provided to detect exploitation attempts or presence of the vulnerability directly. However, you can check the installed Plesk version and XML API version to determine if the patch is applied.

  • Check Plesk version via command line: `plesk version`
  • Verify if the Plesk XML API version is 18.0.30 or later; if not, the system is vulnerable.

If updating is not possible, it is recommended to disable the Plesk XML API or restrict access to it to mitigate the risk.

Impact Analysis

This vulnerability can have severe impacts as it allows an authenticated user to gain root-level access on the server.

With full privilege escalation, an attacker can write arbitrary files as root, potentially leading to complete system compromise, unauthorized data access, and disruption of services.

If exploited, it could allow attackers to control the server environment, install malicious software, or steal sensitive information.

Mitigation Strategies

To mitigate the vulnerability CVE-2026-48614 in Plesk's XML API, users should install the latest Plesk updates, specifically version 18.0.30 or later, where the issue is fixed.

If updating is not possible immediately, users should disable the Plesk XML API or restrict access to it as a temporary mitigation measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48614. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart