Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-48614 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-48614 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-48614 is a critical improper authorization vulnerability in the Plesk XML API that allows authenticated users to inject arbitrary configuration directives, leading to arbitrary file write with root privileges and full privilege escalation on affected hosting control panel instances.

Technical Detail

The flaw exists in Plesk's XML API layer, where insufficient authorization controls fail to validate or sanitize configuration directives submitted by authenticated users. An attacker with any level of authenticated API access can craft malicious XML requests that inject arbitrary directives into server-side configuration processing, resulting in arbitrary file writes executed in the context of the root user. Successful exploitation yields complete system compromise, including persistent access, credential harvesting, and lateral movement across hosted environments managed by the affected Plesk instance.

Exploitation Status

No known exploit code has been publicly observed or confirmed as of July 13, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the CVSS score of 9.9 and the post-authentication root write primitive make this a high-priority candidate for weaponization once details become more widely circulated.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability in available intelligence sources as of the publication date.

What To Do

Apply any available Plesk security patches addressing this vulnerability immediately, prioritizing internet-facing Plesk deployments and managed hosting environments where the XML API is accessible. If a patch is not yet available, restrict API access to trusted IP ranges at the network perimeter and disable or rate-limit XML API endpoints where operationally feasible. Audit API authentication logs for anomalous or unexpected configuration-related requests. Monitor file system integrity on Plesk hosts, particularly in directories writable by the Plesk service, for unauthorized changes. Given the root-level write impact, treat any unpatched instance as a high-risk asset and consider temporary isolation from broader network segments until remediation is confirmed.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →