Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Home/CyberSecurity News/Critical Plesk Vulnerability Lets Users Execute Arbitrary Commands
CyberSecurity News

Critical Plesk Vulnerability Lets Users Execute Arbitrary Commands

Key Takeaways A critical vulnerability, CVE-2026-44962, has been identified in Plesk, allowing authenticated users to execute arbitrary commands. The flaw, located in the APS Application Catalog...

Marcus Rodriguez
Marcus Rodriguez
June 1, 2026 3 Min Read
57 0

Key Takeaways

  • A critical vulnerability, CVE-2026-44962, has been identified in Plesk, allowing authenticated users to execute arbitrary commands.
  • The flaw, located in the APS Application Catalog component, stems from an XPath injection issue with a CVSS score indicating high impact.
  • Plesk has released patches in versions 18.0.76.2 and 18.0.75.1, and users are urged to update immediately.
  • A temporary workaround involves disabling the APS Catalog functionality, though it is not a substitute for patching.

Critical Plesk Flaw Enables Arbitrary Command Execution

A newly disclosed critical vulnerability within Plesk, identified as CVE-2026-44962, poses a significant security risk. Researchers have confirmed that this flaw allows authenticated users to execute arbitrary operating system commands on affected servers, raising alarms across the cybersecurity landscape.

Table Of Content

  • Key Takeaways
  • Critical Plesk Flaw Enables Arbitrary Command Execution
  • Understanding the XPath Injection Vulnerability
  • Plesk Releases Patches and Workarounds
  • What You Should Do

Details of the issue, which impacts the APS Application Catalog component, have been published in both the National Vulnerability Database and the GitHub Advisory Database. Due to its potential to severely compromise confidentiality, integrity, and availability, the vulnerability has been assigned a critical CVSS score.

Understanding the XPath Injection Vulnerability

The core of this vulnerability lies in an XPath injection flaw found within the APS Catalog’s search functionality. Specifically, user-supplied input is not properly sanitized before being directly integrated into XPath queries. This oversight, categorized under CWE-643, enables attackers to manipulate the logic of these queries, thereby controlling how data is retrieved from XML-based storage mechanisms.

Practically, this means a low-privileged, authenticated user can exploit this weakness to escalate their privileges and execute arbitrary commands on the underlying server. The attack’s simplicity is concerning; it requires only network access and minimal privileges, with no user interaction necessary. This significantly lowers the barrier for exploitation in real-world scenarios.

Adding to its severity, the vulnerability operates with a “changed scope,” meaning its impact can extend beyond its original security boundaries. Security researchers often highlight the particular danger of XPath injection vulnerabilities in web applications that process XML data, as they can frequently bypass conventional input validation controls. In this specific case, the inadequate neutralization of input allows attackers to craft malicious queries that effectively alter the backend’s execution behavior.

Plesk Releases Patches and Workarounds

Plesk has acknowledged the vulnerability and responded by releasing patched versions to address the flaw. The fix is included in Plesk versions 18.0.76.2 and 18.0.75.1, which were made available in late February 2026. Users are strongly advised to update their installations immediately to mitigate the risk of exploitation.

For environments where immediate patching is not feasible, Plesk has provided a temporary workaround. Administrators can disable the APS Catalog functionality by modifying the panel configuration file located at /usr/local/psa/admin/conf/panel.ini. While this measure can reduce exposure, it is crucial to understand that it does not substitute for applying the official security update.

The vulnerability was responsibly disclosed by security researcher Georgii Shutiaev, who collaborated with Plesk to ensure a coordinated remediation effort. As of the time of publication, there is no public evidence of active exploitation. However, given the attack’s straightforward nature and high potential impact, threat actors could rapidly weaponize it.

Organizations utilizing Plesk, particularly those in shared hosting or multi-tenant environments, should prioritize addressing this vulnerability. This incident underscores the persistent risks associated with improper input handling in web applications and reinforces the critical importance of secure coding practices and timely patch management in minimizing the attack surface.

What You Should Do

  • Update Immediately: Apply Plesk versions 18.0.76.2 or 18.0.75.1 without delay to patch the vulnerability.
  • Implement Temporary Workaround: If immediate patching is not possible, disable the APS Catalog functionality by editing /usr/local/psa/admin/conf/panel.ini. Remember this is a temporary measure.
  • Review Access Controls: Scrutinize and strengthen access controls for authenticated users to limit potential damage from compromised accounts.
  • Monitor for Suspicious Activity: Enhance monitoring for unusual command execution or privilege escalation attempts on Plesk servers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Iran-Linked Hackers Wipe Middle East Orgs’ IT, Backups, and Recovery Systems

Next Post

SideCopy Hackers Target Afghanistan Finance Ministry with XenoRAT Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us