---
schema: 1
kind: vulnerability
title: "CVE-2026-48614 — Plesk XML API code injection: authenticated low-privilege user to root (CVSS 9.9)"
headline: "CCB Belgium flags Plesk XML-API flaw (CVE-2026-48614): any authenticated panel user can reach root"
summary: >
  CVE-2026-48614 is a code-injection flaw (CWE-94) in Plesk's XML API that lets an
  authenticated, low-privilege panel user inject configuration directives and achieve an
  arbitrary file write as root — full local privilege escalation to the hosting server
  (CVSS 9.9). CCB Belgium issued a "patch immediately" advisory; on multi-tenant shared
  hosting the authenticated prerequisite is met by any customer, collapsing tenant
  isolation. Affected < 18.0.30; fixed 18.0.30 through 18.0.78.4 (18.0.79+ unaffected).
  No confirmed in-the-wild exploitation reported.
discovered_at: "2026-07-09T04:32:59Z"
event_date: "2026-07-08"
run_id: 2026-07-09T0409Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, priv-esc, patch-available]
regions: [europe, switzerland]
sectors: [public-sector, telco, technology]
entities: []
cves:
  - id: CVE-2026-48614
    cvss: "9.9"
    epss: null
    type: priv-esc
    vector: local
    auth: post-auth
    status: [patch-available]
    affected: "Plesk < 18.0.30"
    fixed: "18.0.30 – 18.0.78.4 (18.0.79+ unaffected by design)"
sources:
  - url: "https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately"
    publisher: "Centre for Cybersecurity Belgium (CCB)"
    date: "2026-07-08"
    role: primary
  - url: "https://support.plesk.com/hc/en-us/articles/41171817973143-Vulnerability-CVE-2026-48614-in-Plesk-XML-API"
    publisher: "Plesk (vendor PSIRT)"
    date: "2026-07-03"
    role: primary
closed_sources: []
evidence:
  - quote: "An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives."
    publisher: "Centre for Cybersecurity Belgium (CCB)"
  - quote: "The exploitation of this flaw can result in an arbitrary file write as the root user, leading to local privilege escalation (LPE)."
    publisher: "Centre for Cybersecurity Belgium (CCB)"
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "Patch Plesk to 18.0.30+ (or 18.0.79+ for the fully unaffected line) now; if patching is delayed, disable or access-restrict the XML API per CCB/Plesk guidance."
  - "On multi-tenant Plesk installs, monitor XML-API access logs for authenticated accounts issuing calls outside their normal automation pattern, and alert on unexpected root-owned file writes under Plesk config directories immediately after such calls."
migrated_from: null
---

The Centre for Cybersecurity Belgium (CCB) published a standalone "patch immediately" advisory on 8 July for **CVE-2026-48614**, a `CWE-94` (improper control of code generation / code injection) flaw in Plesk's XML API ([CCB, 2026-07-08](https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately)). An authenticated, low-privilege panel user can send a crafted XML-API request that bypasses the intended authorization boundary and injects arbitrary configuration directives into upstream config generation; because input neutralisation is broken, this yields an arbitrary file write performed as **root**, i.e. local privilege escalation from any authenticated panel account to full root on the hosting server. CCB scores it CVSS 3.1 9.9 (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`) ([CCB, 2026-07-08](https://ccb.belgium.be/advisories/warning-improper-authorization-vulnerability-plesk-xml-api-patch-immediately)). Plesk's own advisory confirms the CVE and the LPE impact, thanks independent researcher Georgii Shutiaev for the disclosure, and lists affected versions below 18.0.30, patched in 18.0.30 through 18.0.78.4, with 18.0.79 and later unaffected ([Plesk, 2026-07-03](https://support.plesk.com/hc/en-us/articles/41171817973143-Vulnerability-CVE-2026-48614-in-Plesk-XML-API)). Neither CCB nor Plesk reports in-the-wild exploitation at publication. Mapped to `T1068 Exploitation for Privilege Escalation`.

The prerequisite is only a valid low-privilege authenticated session — and that is the point for defenders: on multi-tenant shared-hosting Plesk installs, every hosting customer already holds such an account, so the flaw collapses tenant isolation and turns any customer into a path to root on the shared server and thus to every co-tenant's sites and data. Plesk is broadly deployed across Swiss and EU web-hosting providers and public-sector/SME web infrastructure, which is why CCB — a national authority (Admiralty A) — escalated it rather than leaving it to routine patching.

**Defender takeaway:** treat this as beyond the normal patch cadence wherever a Plesk panel grants any untrusted party authenticated access. Patch to a fixed line now; where that must wait, disable or tightly access-restrict the XML API. Hunt Plesk XML-API access logs (e.g. the `sw-cp-server` access log / `/usr/local/psa/admin` RPC endpoint, version-dependent) for authenticated accounts making out-of-pattern XML-API calls, and correlate with unexpected root-owned writes under Plesk's config directories.
