← back
CVE-2026-48614criticalCWE-94

CVE-2026-48614

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.9epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
WebPros · Plesk