CVE-2026-56843

CRITICAL

Webpros Plesk < 18.0.78.4 - Insufficiently Protected Credentials

Title source: rule
STIX 2.1

Description

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.

Scores

CVSS v3 9.9
EPSS 0.0036
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-522
Status published
Products (1)
Webpros/Plesk 10.4 - 18.0.78.4
Published Jul 08, 2026
Tracked Since Jul 08, 2026