CVE-2026-56843: Cleartext FTP Password Exposure in Plesk's XML API, 9.9 rating 🔥
Exposure of cleartext FTP credentials is possible in Plesk's XML API, which may allow a low-privileged attacker to upload malicious files and execute arbitrary code remotely (RCE) as another tenant's system user.
Search at Netlas.io:
👉 Link: https://nt.ls/MZtlo
👉 Dork: tag.name:"plesk"
Vendor's advisory:
https://support.plesk.com/hc/en-us/articles/41178305151255-Vulnerability-in-Plesk-XML-API-Cleartext-FTP-Password-Exposure
Post #591
621

- ❤ 3
- 🔥 3