Executive brief
Plesk's DNS zone management functionality, a critical component used by hosting providers to manage domain DNS records, contains an improper input validation vulnerability. An authenticated attacker can exploit this flaw to read sensitive local files from the server and escalate their privileges, potentially gaining complete control over the hosting infrastructure and customer data.
Technical details
The vulnerability is an improper neutralization of special elements (CWE-74 class) in Plesk's DNS zone management functionality. The root cause is insufficient input validation and sanitization when processing user-supplied input in DNS zone configuration operations. An authenticated user with DNS management permissions can inject specially crafted input to bypass security controls, achieve arbitrary file disclosure from the server filesystem, and escalate privileges. The attack requires authentication but is remotely exploitable over the network. A patch or update from Plesk is required to remediate this issue.
Affected products
- Plesk Plesk <UNKNOWN>
Timeline
- 2026-08-26: disclosed