CVE-2026-48614

CRITICAL

Webpros Plesk < 18.0.78 - Improper Control of Generation of Code ('Code Injection')

Title source: rule
STIX 2.1

Description

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

Scores

CVSS v3 9.9
EPSS 0.0033
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
WebPros/Plesk < 18.0.78
Published Jul 06, 2026
Tracked Since Jul 06, 2026