logo

Severe Plesk Privilege Escalation Flaw Patched in Linux Versions

ID: fd98a25a-9e3a-59aa-a29e-84be5ffd8435

STIX ID: report--fd98a25a-9e3a-59aa-a29e-84be5ffd8435

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

A critical XPath injection vulnerability (CVE-2026-44962) in the Plesk APS Application Catalog allows authenticated low-privileged users to execute arbitrary OS commands and achieve administrative control on affected Linux servers; vendor patches (18.0.76.2 and 18.0.75.1) have been released and a temporary mitigation is to disable the APS subsystem in /usr/local/psa/admin/conf/panel.ini.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.