No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Root Privilege Escalation via Plesk XML API Abuse | Plesk: Plesk: Privilege escalation via improper authorization in XML API |
| Weaknesses | CWE-15 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 07 Jul 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Root Privilege Escalation via Plesk XML API Abuse |
Mon, 06 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros plesk |
|
| Vendors & Products |
Webpros
Webpros plesk |
Mon, 06 Jul 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-07-06T17:39:05.008Z
Reserved: 2026-05-22T15:00:09.276Z
Link: CVE-2026-48614
Updated: 2026-07-06T17:39:00.753Z
No data.
OpenCVE Enrichment
Updated: 2026-07-26T20:30:03Z