CVE-2026-58046
WebPros · Plesk
A blind SQL injection vulnerability in the Plesk XML-RPC API allows an authenticated low-privileged user to read arbitrary data from the Plesk database.
Executive summary
A critical SQL injection vulnerability in the WebPros Plesk XML-RPC API allows authenticated users to read arbitrary database information and compromise the panel.
Vulnerability
The vulnerability is a blind SQL injection flaw (CWE-89) within the XML-RPC API. It requires the attacker to be authenticated as a low-privileged user, at which point they can manipulate database queries to extract sensitive information.
Business impact
Successful exploitation can lead to a full compromise of the Plesk management panel, allowing attackers to access sensitive configuration data, user credentials, and potentially administrative controls. The CVSS score of 9.9 underscores the extreme severity, as it facilitates unauthorized data exfiltration and control over the hosting environment.
Remediation
Immediate Action: Update the WebPros Plesk installation to the latest available version to resolve the API vulnerability.
Proactive Monitoring: Review database query logs for unusual patterns, specifically those involving XML-RPC API calls that deviate from standard operational behavior.
Compensating Controls: Restrict access to the Plesk XML-RPC API to authorized network ranges and ensure that low-privileged user accounts are strictly managed and audited.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a severe risk to the integrity of the Plesk management environment. Administrators must apply the necessary updates provided by WebPros immediately to mitigate the risk of unauthorized database access and potential system-wide compromise.