WebPros disclosed CVE-2026-58046, a blind SQL injection flaw in the Plesk XML-RPC API that affects all Plesk versions earlier than 18.0.79.4. The vulnerability allows a remote authenticated user with low privileges, including customer- or reseller-level access, to query the Plesk database and read arbitrary contents. Plesk warned that exposed data can include administrator credentials, creating a path to full server compromise.
The issue is classified as CWE-89 and carries a CVSS v3.1 vector of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting high impact across confidentiality, integrity, and availability. Plesk has patched the flaw in 18.0.79.4 and urged administrators to update immediately; for systems that cannot be upgraded at once, the vendor recommended mitigations in panel.ini to enforce strict API protocol version validation or to restrict XML API access to trusted IP addresses only. The Canadian Centre for Cyber Security also issued advisory AV26-761, directing organizations to apply the vendor guidance.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-761 about CVE-2026-58046, warning that WebPros Plesk is affected by a blind SQL injection flaw in the XML-RPC API. The advisory told users and administrators to review vendor guidance and apply updates as available.
Plesk disclosed CVE-2026-58046 as a blind SQL injection vulnerability affecting versions earlier than 18.0.79.4 and said it could allow low-privileged authenticated users to read arbitrary database contents, including administrator credentials. Plesk stated the issue was patched in version 18.0.79.4 and provided mitigations for systems that could not be upgraded immediately.
Plesk said CVE-2026-58046, a blind SQL injection flaw in the XML-RPC API, was responsibly disclosed by Aziz Knani. The source does not provide a date for the disclosure event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcesupport.plesk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.