CVE-2026-58046
CRITICAL
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Jul 30, 2026
Vendor
unknown
Description
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.