An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
References
Configurations
No configuration.
History
06 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-06 18:16
Updated : 2026-07-06 19:41
NVD link : CVE-2026-48614
Mitre link : CVE-2026-48614
CVE.ORG link : CVE-2026-48614
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
