SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-58046

CRITICAL · CVSS 9.9 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Plesk XML-RPC API is vulnerable to SQL injection due to improper input handling, enabling a remote authenticated low-privileged user to access sensitive data from the Plesk database. This flaw can lead to a complete compromise of the Plesk panel, making it critical for organizations using Plesk to prioritize immediate remediation. System administrators and security teams should address this vulnerability to protect against potential data breaches and unauthorized access.

CVE
CVE-2026-58046
Severity
CRITICAL
CVSS
9.9
EPSS
0.35%

Original NVD Description

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.