CVE-2026-56843Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-07-08); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-07-08: 4Mentions · 2026-07-09: 1Mentions · 2026-07-16: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-08: 4Technical Details · 2026-07-09: 107-0807-0907-16
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-084
Disclosure4
2026-07-091
Patch1
2026-07-161
Disclosure1
Full discourse6 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-56843: Cleartext FTP Password Exposure in Plesk's XML API, 9.9 rating 🔥 Exposure of cleartext FTP credentials is possible in Plesk's XML API, which may allow a low-privileged attacker to upload malicious files and execute arbitrary code remotely (RCE) as another tenant's system user. 👉 https://nt.ls/MZtlo

    Post summary

    CVE-2026-56843 exposes cleartext FTP credentials via Plesk’s XML API, allowing low‑privileged attackers to upload malicious files and achieve remote code execution.

    0602291.7K
    7.7K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Plesk ❗ CVE-2026-56843 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-plesk-2/ https://t.co/O8tfKrltYl

    Post summary

    The tweet announces a new vulnerability in Plesk products, identified as CVE-2026-56843, and directs readers to external links for further information.

    00000184
    6.7K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-56843 (CVSS 9.9) impacts Plesk <18.0.78.4: low-priv accounts can query domains they do not own. Update immediately if you use Plesk. https://nvd.nist.gov/vuln/detail/CVE-2026-56843 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/nYqWLDAl2I

    Post summary

    A high‑scoring CVE (CVSS 9.9) allows low‑privilege Plesk users to query domains they do not own, and users are urged to update immediately.

    0000052
    91 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Plesk XML-RPC authorization bypass enables cross-tenant credential leak & code execution (CVE-2026-56843) CVE-2026-56843 is an incorrect authorization flaw in the WebPros Plesk XML-RPC API (legacy protocol paths) affecting multi-tenant hosting environments. The root cause is insufficient ownership enforcement combined with bypassable schema validation for older XML-RPC protocol versions, allowing access to objects outside the caller’s tenant boundary. An attacker only needs a low-privileged authenticated customer account and can abuse XML-RPC requests to enumerate/lookup domains they do not own and pull associated data. Impact includes disclosure of other tenants’ cleartext-stored FTP credentials and potential lateral movement culminating in code execution as another tenant’s system user. 👉 Affected: WebPros Plesk before 18.0.78.4 | Upgrade to 18.0.78.4

    Post summary

    CVE-2026-56843 is an authorization bypass in the Plesk XML‑RPC API that lets low‑privileged accounts enumerate other tenants’ domains and retrieve cleartext FTP credentials, potentially leading to code execution; the issue is fixed by upgrading to Plesk 18.0.78.4.

    00000140
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56843 Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, becaus… https://www.cve.org/CVERecord?id=CVE-2026-56843 ----- Traducción: CVE-2026-56843 Aut… http://infoflow.cloud`

    Post summary

    CVE-2026-56843 is announced as an authorization flaw in WebPros Plesk XML‑RPC API, letting low‑privileged users discover domains they do not own. No PoC, exploit, patch, or active exploitation details are provided.

    0000043
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56843 Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, becaus… https://www.cve.org/CVERecord?id=CVE-2026-56843

    Post summary

    The statement announces CVE-2026-56843 as an authorization flaw in Plesk’s XML‑RPC API allowing low‑privileged users to query unowned domains. No PoC, exploit, active usage, or patch details are provided.

    00000645
    57.8K followersView on X

Explore more