top of page
perceptive_background_267k.jpg

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Ple…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 07:01:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage

CVE-2026-58046 describes a critical SQL injection vulnerability in the Plesk XML-RPC API caused by improper input neutralization. A remote authenticated user with low privileges can exploit this flaw to perform blind SQL injection attacks. The vulnerability allows reading arbitrary data from the Plesk database, potentially exposing sensitive configuration and credentials. Successful exploitation leads to full compromise of the Plesk control panel. The vulnerability requires only authenticated low-privileged access, lowering the barrier for exploitation. Plesk has published a dedicated advisory detailing the issue and remediation steps. The impact is rated high due to the potential for complete panel takeover.

Technical details

Mitigation steps:

Affected products:

Plesk XML-RPC API
Plesk

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page