CVE-2026-64637

WebPros · Plesk

Plesk before 18.0.80.1 contains an improper privilege management vulnerability in its XML-RPC API that allows resellers to escalate to administrative root access.

Executive summary

An improper privilege management vulnerability in the Plesk XML-RPC API allows authenticated resellers to escalate their privileges to the root administrator.

Vulnerability

The vulnerability exists in the XML-RPC API due to improper privilege handling. An authenticated reseller can exploit this flaw to bypass restriction checks and obtain a session for the root user account.

Business impact

The CVSS score of 9.9 underscores the severe impact of this privilege escalation, which grants total control over the server environment. Successful exploitation allows a lower-privileged reseller to gain full administrative rights, potentially leading to total system compromise, unauthorized access to all hosted websites, and complete database control.

Remediation

Immediate Action: Update WebPros Plesk to version 18.0.80.1 or later to apply the necessary security fixes to the XML-RPC API.

Proactive Monitoring: Review administrative audit logs for unusual session activity or suspicious XML-RPC requests originating from reseller accounts.

Compensating Controls: If patching is delayed, restrict access to the XML-RPC API to trusted IP addresses and enforce strong multi-factor authentication for all reseller and administrator accounts.

Exploitation status

Public Exploit Available: Unknown — there is no confirmed public exploit in the available data.

Analyst recommendation

Security administrators must update Plesk installations to the specified version immediately to prevent unauthorized privilege escalation. Given the potential for complete system compromise, monitoring for anomalous API usage in the interim is critical to detect potential exploitation attempts.