top of page
perceptive_background_267k.jpg

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Ple…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 07:01:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage

CVE-2026-58046 describes a critical SQL injection vulnerability in the Plesk XML-RPC API caused by improper input neutralization. A remote authenticated user with low privileges can exploit this flaw to perform blind SQL injection attacks. The vulnerability allows reading arbitrary data from the Plesk database, potentially exposing sensitive configuration and credentials. Successful exploitation leads to full compromise of the Plesk control panel. The vulnerability requires only authenticated low-privileged access, lowering the barrier for exploitation. Plesk has published a dedicated advisory detailing the issue and remediation steps. The impact is rated high due to the potential for complete panel takeover.

Technical details

Mitigation steps:

Affected products:

Plesk XML-RPC API
Plesk

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page