CVE-2026-56843 – WebPros Plesk
“When authorization fails, one account can become the gateway to the entire server.”
WebPros has released security updates for Plesk to address two Critical authorization vulnerabilities affecting its XML-based management interfaces. CVE-2026-48614 allows an authenticated user to inject arbitrary configuration directives through the Plesk XML API, leading to arbitrary file writes as root and full privilege escalation on the underlying server. CVE-2026-56843 affects the XML-RPC API and allows a low-privileged customer to access domains they do not own, exposing other tenants’ FTP credentials stored in cleartext. The disclosed credentials could then be used to execute code under another tenant’s system account.
CVE-2026-48614 has a CVSS score of 9.9, which is Critical severity. CVE-2026-56843 has a CVSS score of 9.9, which is Critical severity. Based on the information provided, there is no verified exploitation associated with either vulnerability. Organizations using affected versions of Plesk should prioritize installing the latest updates to protect against privilege escalation and cross-tenant compromise.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-522