← Back to browse · API

CVE-2026-44962

Severity
CRITICAL
CVSS
9.9
EPSS
0.00686
Risk score
39.84
CISA KEV
No
PoC
No
Published
2026-05-29
Modified
2026-08-14
First seen
2026-08-05
Aliases
EUVD-2026-33344, GHSA-2785-QQ7P-X3CJ
Products
Plesk:Plesk 0 <18.0.75.1, Plesk:Plesk 0 <18.0.76.2, Plesk:Plesk 18.0.75.1 <18.0.75.1, Plesk:Plesk 18.0.76.2 <18.0.76.2
Sources
euvd EUVD-2026-33344
nvd CVE-2026-44962

Description

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.

References