CVE-2026-44962 — Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.
Platform
Plesk
CVE Record
CVE-2026-44962
CVSS Score
9.9/10
Published
29 May 2026
Views
17
Primary source: Review the official advisory at nvd.nist.gov
Go to Source
Summary
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.