Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48614

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 9.9
EPSS Низкий

Описание

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

A flaw was found in Plesk. An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives. This can result in arbitrary file write as root, leading to full privilege escalation on the underlying server.

Отчет

Critical:An improper authorization vulnerability exists in the Plesk XML API that allows an authenticated user to inject arbitrary configuration directives, potentially resulting in arbitrary file writes as root and privilege escalation. Although the go-acme/lego dependency is present, Red Hat OpenShift Dev Spaces does not ship or use the affected Plesk functionality. Therefore, the vulnerable code path is not exposed in this product.

Меры по смягчению последствий

Red Hat OpenShift Dev Spaces is not affected because it does not ship or rely on Plesk or expose the Plesk XML API. The vulnerable functionality resides within the Plesk-specific integration of the go-acme/lego library, which is not used by the product. Authentication is also required to exploit the vulnerability. No product changes are required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-15
https://bugzilla.redhat.com/show_bug.cgi?id=2497412Plesk: Plesk: Privilege escalation via improper authorization in XML API

EPSS

Процентиль: 25%
0.0033
Низкий

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
24 дня назад

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

CVSS3: 9.9
github
24 дня назад

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

EPSS

Процентиль: 25%
0.0033
Низкий

9.9 Critical

CVSS3