CVE-2026-44962: Critical severity Plesk Plesk vulnerability
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Plesk APS Application Catalogfrom your environment.Uninstall or disable the APS Application Catalog component if it is not required to eliminate the vulnerable search functionality.
- Configuration
Disable the APS Application Catalog search functionality to prevent user-supplied input from being interpolated into XPath queries (mitigates the XPath injection leading to command execution).
Plesk APS Application Catalog search functionality = disabled - Compensating control
Restrict access to Plesk management and APS features to trusted administrator IPs or networks (firewall/ACL) and limit the ability of low-privileged authenticated users to access the APS Application Catalog until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44962?
CVE-2026-44962 has a critical severity rating of 10.
What is CVE-2026-44962?
CVE-2026-44962 is an XPath injection vulnerability in Plesk's APS Application Catalog search functionality that allows unauthorized command execution.
How do I fix CVE-2026-44962?
To fix CVE-2026-44962, ensure that Plesk is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-44962?
CVE-2026-44962 affects authenticated, low-privileged users of Plesk who can exploit the vulnerability to execute commands.
What are the risks of not addressing CVE-2026-44962?
Not addressing CVE-2026-44962 may allow attackers to execute arbitrary operating system commands, compromising the security of the server.