CVE-2026-56843
CRITICALWebpros Plesk < 18.0.78.4 - Insufficiently Protected Credentials
Title source: ruleDescription
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.
References (1)
Core 1
Scores
CVSS v3
9.9
EPSS
0.0036
EPSS Percentile
29.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-522
Status
published
Products (1)
Webpros/Plesk
10.4 - 18.0.78.4
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026