Description
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.
Published: 2026-07-08
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a weakness that allows improper disclosure of cleartext FTP passwords because ownership checks are applied only to specific lookup filters and schema validation is skipped for legacy protocol versions. An authenticated customer with low privileges can therefore request domain information that belongs to other tenants, exposing FTP credentials stored in cleartext. Those credentials can be used to run code as another tenant’s system user, compromising both confidentiality and integrity.

Affected Systems

WebPros Plesk instances running any version earlier than 18.0.78.4 are affected. The flaw applies to all tenants that use the legacy XML‑RPC protocol and allows them to read domain data they do not own.

Risk and Exploitability

The CVSS score of 9.9 categorises the issue as Critical, indicating a high potential impact if exploited. The EPSS score is less than 1 %, suggesting that exploitation attempts are infrequent. The vulnerability is not listed in CISA KEV. A likely attack vector involves a low‑privileged authenticated customer logging into the Plesk control panel, sending a legacy XML‑RPC request that bypasses schema validation, harvesting exposed FTP credentials, and then using those credentials to execute code as the system user of another tenant.

Generated by OpenCVE AI on July 28, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Plesk to version 18.0.78.4 or later, where the authorization check for all lookup filters is enforced and schema validation is performed for legacy protocols.
  • Disable or block access to legacy XML‑RPC protocol endpoints so that only validated and properly authorized requests are processed.
  • Reconfigure Plesk to encrypt stored FTP credentials and migrate any historical credentials that are currently in cleartext to secure storage, thereby eliminating the risk of credential exposure.

Generated by OpenCVE AI on July 28, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant FTP Credential Disclosure via XML‑RPC API

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant FTP Credential Disclosure via XML‑RPC API

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant FTP Credential Exposure via XML‑RPC API

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant FTP Credential Exposure via XML‑RPC API

Tue, 14 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Cross-tenant Disclosure of Cleartext FTP Credentials via XML‑RPC API in Plesk

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Cross-tenant Disclosure of Cleartext FTP Credentials via XML‑RPC API in Plesk

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant FTP Credential Exposure via Weak XML‑RPC Authorization in Plesk

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant FTP Credential Exposure via Weak XML‑RPC Authorization in Plesk

Fri, 10 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Cross-Tenant FTP Credential Disclosure via XML-RPC API Authorization Bypass

Thu, 09 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Cross-Tenant FTP Credential Disclosure via XML-RPC API Authorization Bypass

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros plesk
Vendors & Products Webpros
Webpros plesk

Wed, 08 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-08T13:04:17.023Z

Reserved: 2026-06-23T15:00:03.632Z

Link: CVE-2026-56843

cve-icon Vulnrichment

Updated: 2026-07-08T13:04:13.970Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:15:03Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials