CVE-2026-44962 Details
Description
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.
An XPath injection vulnerability has been identified in Plesk's APS Application Catalog search feature. This issue arises because user input is incorporated into XPath queries without adequate sanitization. As a result, an authenticated, low-privileged user could execute arbitrary operating system commands on the server, leading to local privilege escalation.
Plesk has released fixed versions 18.0.76.2 and 18.0.75.1. Users should update Plesk to these versions. If an immediate upgrade is not possible, as a temporary workaround, disable the APS application catalog by adding 'enabled = off' under the '[aps]' section in the '/usr/local/psa/admin/conf/panel.ini' file.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.plesk.com/hc/en-us/articles/38633651286679-Vulnerability-CVE-2026-44962-in-Plesk-s-APS-Catalog | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-643 | Improper Neutralization of Data within XPath Expressions ('XPath Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | [email protected] |
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | New CVE Received | [email protected] |