Netlas.io[verified]@Netlas_ioDisclosure
CVE-2026-56843 exposes cleartext FTP credentials via Plesk’s XML API, allowing low‑privileged attackers to upload malicious files and achieve remote code execution.
ADK Cyber[verified]@ADKCyberPatch
A high‑scoring CVE (CVSS 9.9) allows low‑privilege Plesk users to query domains they do not own, and users are urged to update immediately.
Upwind Security MDR[verified]@UpwindMDRDisclosure
CVE-2026-56843 is an authorization bypass in the Plesk XML‑RPC API that lets low‑privileged accounts enumerate other tenants’ domains and retrieve cleartext FTP credentials, potentially leading to code execution; the issue is fixed by upgrading to Plesk 18.0.78.4.
CERT-PY@CERTpyDisclosure
The tweet announces a new vulnerability in Plesk products, identified as CVE-2026-56843, and directs readers to external links for further information.
Infoflowcloud@infoflowcloudDisclosure
CVE-2026-56843 is announced as an authorization flaw in WebPros Plesk XML‑RPC API, letting low‑privileged users discover domains they do not own. No PoC, exploit, patch, or active exploitation details are provided.
CVE@CVEnewDisclosure
The statement announces CVE-2026-56843 as an authorization flaw in Plesk’s XML‑RPC API allowing low‑privileged users to query unowned domains. No PoC, exploit, active usage, or patch details are provided.