CVE-2026-56843

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.
Configurations

No configuration.

History

08 Jul 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 01:16

Updated : 2026-07-10 18:57


NVD link : CVE-2026-56843

Mitre link : CVE-2026-56843

CVE.ORG link : CVE-2026-56843


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials