CVE-2026-48614: WebPros Plesk

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

Affected products

  • WebPros Plesk: before 18.0.78 (fixed in 18.0.78)

Published 2026-07-06. Last modified 2026-07-06.