Executive brief
A security flaw in the Plesk web hosting control panel allows one customer to access the private login credentials of other customers hosted on the same server. By exploiting this issue, a low-privileged user can view cleartext FTP passwords for domains they do not own, potentially leading to a full takeover of other websites and data. This poses a significant risk to service providers as it allows for cross-tenant data breaches and unauthorized server access.
Technical details
An incorrect authorization vulnerability exists in the Plesk XML-RPC API due to inconsistent ownership enforcement across different lookup filters. Specifically, schema validation is bypassed when using legacy protocol versions, allowing authenticated users with low privileges to query domain information outside of their own tenant scope. This flaw leads to the exposure of cleartext FTP credentials for unauthorized domains. An attacker can leverage these credentials to gain system-level access as another tenant's user, effectively achieving cross-tenant code execution. The issue is resolved in Plesk version 18.0.78.4.
Affected products
- WebPros Plesk 10.4 to 18.0.78.3
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory