Junglewise Threat Intelligence

CVE-2026-58046: WebPros Plesk SQL injection in XML-RPC API

CVE-2026-58046 · Severity: critical · CVSS 9.9 · Published 2026-07-30

Vendors: WebPros.

Executive brief

Plesk, a widely used web hosting control panel, contains a security vulnerability in its management interface. An attacker with low-level access to the system can exploit this flaw to gain unauthorized access to the underlying database. This could lead to a complete takeover of the hosting panel, allowing the attacker to access sensitive customer data, modify website configurations, or disrupt services.

Technical details

A blind SQL injection vulnerability exists in the Plesk XML-RPC API due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is reachable via the XML-RPC interface by a remote attacker with low-privileged authentication credentials. By sending specially crafted requests, an attacker can execute arbitrary SQL queries against the Plesk database. This allows for the exfiltration of sensitive administrative data and can lead to a full compromise of the management panel. The issue is addressed in Plesk version 18.0.79.4.

Affected products

  • WebPros Plesk < 18.0.79.4

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References