securityonline.info 6/1/2026, 7:21:17 AM · external

Plesk CVE-2026-44962 Flaw Lets Low Priv Users Gain Server Access

Plesk CVE-2026-44962 Flaw Lets Low Priv Users Gain Server Access
CyberSIXT Evidence Panel
Primary Source support.plesk.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability (CVE-2026-44962) has been discovered in Plesk, a popular web hosting control panel, that allows low-privileged users to escalate privileges and execute arbitrary commands on affected Linux servers. This security flaw is tied to the XPath injection within the APS Application Catalog search functionality, earning a maximum severity score of CVSS 10.

Plesk has issued patches in versions 18.0.76.2 and 18.0.75.1, but users experiencing delays in implementing these updates must manually disable the vulnerable APS subsystem by modifying the panel.ini configuration file. Regular patch management practices are advised to maintain server security.

View Primary Source Via securityonline.info

Article by CyberSIXT