CVE-2026-48614
CRITICALWebpros Plesk < 18.0.78 - Improper Control of Generation of Code ('Code Injection')
Title source: ruleDescription
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
References (1)
Core 1
Scores
CVSS v3
9.9
EPSS
0.0033
EPSS Percentile
25.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
WebPros/Plesk
< 18.0.78
Published
Jul 06, 2026
Tracked Since
Jul 06, 2026