<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Plesk - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/plesk/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 30 Jul 2026 15:30:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/plesk/feed.xml" rel="self" type="application/rss+xml"/><item><title>Blind SQL Injection Vulnerability in Plesk XML-RPC API</title><link>https://feed.craftedsignal.io/briefs/2026-07-plesk-sql-injection/</link><pubDate>Thu, 30 Jul 2026 15:30:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-plesk-sql-injection/</guid><description>A blind SQL injection vulnerability, tracked as CVE-2026-58046, affects the Plesk XML-RPC API, potentially allowing unauthenticated attackers to execute arbitrary database queries.</description><content:encoded><![CDATA[<p>WebPros has issued a security advisory regarding a high-severity blind SQL injection vulnerability affecting the Plesk control panel, specifically within its XML-RPC API. The vulnerability, identified as CVE-2026-58046, impacts all Plesk versions prior to 18.0.79.4. This flaw permits an unauthenticated attacker to inject malicious SQL commands into the API, potentially leading to unauthorized data access, database modification, or sensitive information disclosure from the Plesk backend. Administrators are urged to update to version 18.0.79.4 or later to mitigate this risk. Because the vulnerability lies within the API interface, it is reachable over the network and does not require local system access or elevated user privileges, making it a priority for immediate patching in internet-facing deployments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-58046 allows an unauthenticated remote attacker to execute arbitrary SQL queries against the Plesk database. This could lead to full unauthorized access to site configurations, user credentials, database contents, and other administrative data managed by Plesk. Such access could result in comprehensive data exfiltration or total compromise of hosted services. Organizations running legacy versions of Plesk are at risk if their API endpoints are accessible to untrusted networks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update all Plesk instances to version 18.0.79.4 or newer immediately to remediate CVE-2026-58046.</li>
<li>Review web server access logs for anomalous POST requests directed at XML-RPC API endpoints, specifically looking for common SQL injection characters (such as single quotes, semicolons, or sleep commands) in API payloads.</li>
<li>Restrict network access to the Plesk administrative interface and API endpoints to trusted IP addresses using firewall rules or ACLs to minimize the attack surface until patching is complete.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>sql-injection</category><category>vulnerability</category></item></channel></rss>