CVE-2026-58046: SQL Injection
Published Jul 30, 2026
·Updated
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
Affected Software
1 affected component
Plesk Plesk
Event History
Jul 30, 2026
CVE Published
via MITRE·06:02 AM
Data Sourced
via MITRE·06:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-58046?
CVE-2026-58046 has a critical severity rating of 9.9.
2
What type of vulnerability is CVE-2026-58046?
CVE-2026-58046 is classified as an SQL Injection vulnerability.
3
How does CVE-2026-58046 affect systems?
CVE-2026-58046 allows a remote authenticated low-privileged user to perform SQL injection, leading to potential full compromise of the Plesk panel.
4
How do I fix CVE-2026-58046?
To fix CVE-2026-58046, update your Plesk installation to the latest version provided by the vendor.
5
Who is affected by CVE-2026-58046?
CVE-2026-58046 affects any system using Plesk that has the XML-RPC API enabled and is vulnerable to SQL injection.