


Perceptive Security
SOC/SIEM Consultancy

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Ple…
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 09:01:16
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage
CVE-2026-58046 describes a critical SQL injection vulnerability in the Plesk XML-RPC API caused by improper input neutralization. A remote authenticated user with low privileges can exploit this flaw to perform blind SQL injection attacks. The vulnerability allows reading arbitrary data from the Plesk database, potentially exposing sensitive configuration and credentials. Successful exploitation leads to full compromise of the Plesk control panel. The vulnerability requires only authenticated low-privileged access, lowering the barrier for exploitation. Plesk has published a dedicated advisory detailing the issue and remediation steps. The impact is rated high due to the potential for complete panel takeover.
Technical details
Mitigation steps:
Affected products:
Plesk XML-RPC API
Plesk
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58046
https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
