Impact
An improper authorization flaw in the Plesk XML API allows an attacker to inject arbitrary configuration directives, leading to arbitrary file write as root. The vulnerability combines a lack of proper authorization checks (CWE-15) with a code-injection weakness (CWE-94), enabling an attacker to grant themselves full system privileges and compromise server integrity.
Affected Systems
The vulnerability affects WebPros Plesk servers that expose the XML API. All Plesk versions lacking the patch are potentially vulnerable; specific build numbers are not listed in the advisory.
Risk and Exploitability
The likely attack vector is an authenticated user accessing the Plesk XML API, which is typically achieved via local or internal network access; this inference is based on the description that the attacker must be authenticated. The CVSS score of 9.9 reflects critical severity, while the EPSS score of less than 1% indicates a low current exploitation probability. Although the vulnerability is not listed in the CISA KEV catalog, the combination of high impact and critical confidentiality, integrity, and availability risks makes it a priority for mitigation.
OpenCVE Enrichment