Executive brief
Plesk, a widely used web hosting control panel, contains a critical security flaw in its management interface. An authorized user can exploit this weakness to gain full administrative control over the entire server. This could lead to the theft of sensitive customer data, complete service disruption, or the installation of malicious software across all websites hosted on the platform.
Technical details
An improper authorization vulnerability exists in the Plesk XML API, classified as a code injection flaw (CWE-94). The vulnerability allows an authenticated user with low-level access to inject arbitrary configuration directives into the system. This capability can be leveraged to perform arbitrary file writes with root-level permissions, leading to a complete compromise of the underlying server and full privilege escalation. The attack is reachable over the network and requires only basic user authentication. The issue is addressed in Plesk version 18.0.78.
Affected products
- WebPros Plesk < 18.0.78
Timeline
- 2026-07-06: advisory: Initial disclosure by HackerOne and NVD publication.
- 2026-07-06: patched: Vulnerability addressed in version 18.0.78.