Executive brief
Plesk, a widely used web hosting control panel, contains a security flaw in its application catalog search feature. An attacker with basic user access can exploit this to take full control of the underlying server and execute unauthorized commands. This could lead to a total compromise of the hosting environment, including access to other customers' data and websites.
Technical details
An XPath injection vulnerability exists in the APS Application Catalog search functionality of Plesk. The flaw is caused by improper sanitization of user-supplied input before it is interpolated into XPath queries (CWE-643). An authenticated, low-privileged attacker can exploit this by submitting crafted search queries to execute arbitrary operating system commands on the server. This leads to local privilege escalation and a full system compromise. The vulnerability is reachable over the network and has been assigned a CVSS score of 9.9 due to the high impact on confidentiality, integrity, and availability.
Affected products
- Plesk Plesk
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory