2026-07-09NOTABLECCB Belgium flags Plesk XML-API flaw (CVE-2026-48614): any authenticated panel user can reach root
Plesk XML API code injection (CWE-94), authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected)
cve · CVE-2026-48614
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
CCB Belgium flags Plesk XML-API flaw (CVE-2026-48614): any authenticated panel user can reach root
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, telco, technology · regions: europe, switzerland
Sources cited
2
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-48614, newest first. Check the date before acting on an older one.
- Patch Plesk to 18.0.30+ (or 18.0.79+ for the fully unaffected line) now; if patching is delayed, disable or access-restrict the XML API per CCB/Plesk guidance.2026-07-09CVE-2026-48614
- On multi-tenant Plesk installs, monitor XML-API access logs for authenticated accounts issuing calls outside their normal automation pattern, and alert on unexpected root-owned file writes under Plesk config directories immediately after such calls.2026-07-09CVE-2026-48614
Defender insights
What each entry about CVE-2026-48614 tells a defender to do, newest first.
Story timeline
- 2026-07-09CVE-2026-48614, Plesk XML API code injection: authenticated low-privilege user to root (CVSS 9.9)
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Privilege EscalationExploitation for Privilege Escalation
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-09/cve-2026-48614-plesk-xml-api-code-injection-root-lpe · ATT&CK page ↗
Entries about Plesk XML API code injection (CWE-94), authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected) (1)
Where this entity is cited
Source distribution
- ccb.belgium.be1 (50%)
- support.plesk.com1 (50%)
External references
All cited sources (2)
- support.plesk.comprimaryPlesk (vendor PSIRT)https://support.plesk.com/hc/en-us/articles/41171817973143-Vulnerability-CVE-2026-48614-in-Plesk-XML-API
- ccb.belgium.beCentre for Cybersecurity Belgium (CCB)https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately