CVE-2026-48614 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-48614 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-48614 is a critical improper authorization vulnerability in the Plesk XML API that allows authenticated users to inject arbitrary configuration directives, leading to arbitrary file write with root privileges and full privilege escalation on affected hosting control panel instances.
Technical Detail
The flaw exists in Plesk's XML API layer, where insufficient authorization controls fail to validate or sanitize configuration directives submitted by authenticated users. An attacker with any level of authenticated API access can craft malicious XML requests that inject arbitrary directives into server-side configuration processing, resulting in arbitrary file writes executed in the context of the root user. Successful exploitation yields complete system compromise, including persistent access, credential harvesting, and lateral movement across hosted environments managed by the affected Plesk instance.
Exploitation Status
No known exploit code has been publicly observed or confirmed as of July 13, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the CVSS score of 9.9 and the post-authentication root write primitive make this a high-priority candidate for weaponization once details become more widely circulated.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability in available intelligence sources as of the publication date.
What To Do
Apply any available Plesk security patches addressing this vulnerability immediately, prioritizing internet-facing Plesk deployments and managed hosting environments where the XML API is accessible. If a patch is not yet available, restrict API access to trusted IP ranges at the network perimeter and disable or rate-limit XML API endpoints where operationally feasible. Audit API authentication logs for anomalous or unexpected configuration-related requests. Monitor file system integrity on Plesk hosts, particularly in directories writable by the Plesk service, for unauthorized changes. Given the root-level write impact, treat any unpatched instance as a high-risk asset and consider temporary isolation from broader network segments until remediation is confirmed.