Search

Find a vulnerability

Search criteria

    46 vulnerabilities by WebPros

    CVE-2026-93029 (GCVE-0-2026-93029)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:20 – Updated: 2026-10-02 18:12
    VLAI
    Summary
    There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 18:12 UTC
    CWE
    • CWE-79 - Cross-site Scripting (XSS) - Stored
    Impacted products
    Vendor Product Version
    Webpros cPanel Affected: 0 , < 11.138.0.11 (semver)
    Affected: 0 , < 11.136.0.45 (semver)
    Affected: 0 , < 11.134.0.61 (semver)
    Affected: 0 , < 11.110.0.148 (semver)
    Create a notification for this product.
    Webpros WP Squared Affected: 0 , < 11.138.1.13 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93029",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T18:12:23.705554Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T18:12:44.517Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "11.138.0.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.45",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.61",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.110.0.148",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP Squared",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "11.138.1.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "rz1027 (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Cross-site Scripting (XSS) - Stored",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:20:47.333Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://hackerone.com/reports/4047106"
            },
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43845929235351-Security-CVE-2026-93029-Stored-XSS-in-WHM-s-Manage-SSL-Hosts-Interface-September-29-2026"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/138-change-log/#138011"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/136-change-log/#136045"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/134-change-log/#134061"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/110-change-log/#1100148"
            },
            {
              "url": "https://docs.wpsquared.com/changelogs/versions/changelog/#138113"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-93029",
        "datePublished": "2026-10-02T06:20:47.333Z",
        "dateReserved": "2026-09-17T15:00:00.689Z",
        "dateUpdated": "2026-10-02T18:12:44.517Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93697 (GCVE-0-2026-93697)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:20 – Updated: 2026-10-02 18:14
    VLAI
    Summary
    There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 18:12 UTC
    CWE
    • CWE-79 - Cross-site Scripting (XSS) - Stored
    Impacted products
    Vendor Product Version
    Webpros cPanel Affected: 0 , < 11.138.0.11 (semver)
    Affected: 0 , < 11.136.0.45 (semver)
    Affected: 0 , < 11.134.0.61 (semver)
    Affected: 0 , < 11.110.0.148 (semver)
    Create a notification for this product.
    Webpros WP Squared Affected: 0 , < 11.138.1.13 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93697",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T18:12:58.690897Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T18:14:02.299Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "11.138.0.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.45",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.61",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.110.0.148",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP Squared",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "11.138.1.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "rz1027 (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Cross-site Scripting (XSS) - Stored",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:20:44.084Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://hackerone.com/reports/4047787"
            },
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43845930445207-Security-CVE-2026-93697-Stored-XSS-in-WHM-s-Account-Modification-Interfaces-September-29-2026"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/138-change-log/#138011"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/136-change-log/#136045"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/134-change-log/#134061"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/110-change-log/#1100148"
            },
            {
              "url": "https://docs.wpsquared.com/changelogs/versions/changelog/#138113"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-93697",
        "datePublished": "2026-10-02T06:20:44.084Z",
        "dateReserved": "2026-09-18T15:00:00.594Z",
        "dateUpdated": "2026-10-02T18:14:02.299Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93698 (GCVE-0-2026-93698)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:20 – Updated: 2026-10-02 18:14
    VLAI
    Summary
    Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 18:14 UTC
    CWE
    • CWE-78 - OS Command Injection
    Impacted products
    Vendor Product Version
    Webpros cPanel Affected: 0 , < 11.138.0.11 (semver)
    Affected: 0 , < 11.136.0.45 (semver)
    Affected: 0 , < 11.134.0.61 (semver)
    Affected: 0 , < 11.110.0.148 (semver)
    Create a notification for this product.
    Webpros WP Squared Affected: 0 , < 11.138.1.13 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93698",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T18:14:35.329248Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T18:14:48.415Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "11.138.0.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.45",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.61",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.110.0.148",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP Squared",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "11.138.1.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "rz1027 (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:20:33.663Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://hackerone.com/reports/4054291"
            },
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43845931719447-Security-CVE-2026-93698-Vulnerability-in-Multilang-Adminbin-September-29-2026"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/138-change-log/#138011"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/136-change-log/#136045"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/134-change-log/#134061"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/110-change-log/#1100148"
            },
            {
              "url": "https://docs.wpsquared.com/changelogs/versions/changelog/#138113"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-93698",
        "datePublished": "2026-10-02T06:20:33.663Z",
        "dateReserved": "2026-09-18T15:00:00.595Z",
        "dateUpdated": "2026-10-02T18:14:48.415Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87899 (GCVE-0-2026-87899)

    Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-24 03:55
    VLAI
    Summary
    Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 00:00 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    WebPros cPanel Affected: 11.120.0.0 , < 11.134.0.57 (semver)
    Affected: 11.136.0.0 , < 11.136.0.41 (semver)
    Affected: 11.138.0.0 , < 11.138.0.8 (semver)
    Unaffected: 11.134.0.57 , < 11.134.0.57 (semver)
    Unaffected: 11.136.0.41 , < 11.136.0.41 (semver)
    Unaffected: 11.138.0.8 , < 11.138.0.8 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87899",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T03:55:45.144Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.134.0.57",
                  "status": "affected",
                  "version": "11.120.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.41",
                  "status": "affected",
                  "version": "11.136.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.0.8",
                  "status": "affected",
                  "version": "11.138.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.57",
                  "status": "unaffected",
                  "version": "11.134.0.57",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.41",
                  "status": "unaffected",
                  "version": "11.136.0.41",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.0.8",
                  "status": "unaffected",
                  "version": "11.138.0.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ali Mustafa (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250 Execution with Unnecessary Privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T19:52:47.216Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43591715125271"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-87899",
        "datePublished": "2026-09-23T19:52:47.216Z",
        "dateReserved": "2026-09-09T15:00:00.573Z",
        "dateUpdated": "2026-09-24T03:55:45.144Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68492 (GCVE-0-2026-68492)

    Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-24 14:28
    VLAI
    Summary
    An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 14:28 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 18.0.34 , < 18.0.80.8 (semver)
    Affected: 18.0.81 , < 18.0.81.1 (semver)
    Create a notification for this product.
    WebPros Plesk extension "Plesk RESTful API" Affected: 2.4.2 , < 2.4.7 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68492",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T14:28:28.100954Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T14:28:36.450Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.80.8",
                  "status": "affected",
                  "version": "18.0.34",
                  "versionType": "semver"
                },
                {
                  "lessThan": "18.0.81.1",
                  "status": "affected",
                  "version": "18.0.81",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Plesk extension \"Plesk RESTful API\"",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "2.4.7",
                  "status": "affected",
                  "version": "2.4.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ali Mustafa (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the \"Plesk RESTful API\" extension from 2.4.2 before 2.4.7."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-426",
                  "description": "CWE-426 Untrusted Search Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T19:52:47.192Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/43644058632983"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-68492",
        "datePublished": "2026-09-23T19:52:47.192Z",
        "dateReserved": "2026-07-30T15:00:00.609Z",
        "dateUpdated": "2026-09-24T14:28:36.450Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68490 (GCVE-0-2026-68490)

    Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-24 14:28
    VLAI
    Summary
    Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 14:28 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    Impacted products
    Vendor Product Version
    WebPros cPanel Affected: 11.120.0.0 , < 11.134.0.57 (semver)
    Affected: 11.136.0.0 , < 11.136.0.41 (semver)
    Affected: 11.138.0.0 , < 11.138.0.8 (semver)
    Unaffected: 11.134.0.57 , < 11.134.0.57 (semver)
    Unaffected: 11.136.0.41 , < 11.136.0.41 (semver)
    Unaffected: 11.138.0.8 , < 11.138.0.8 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68490",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T14:28:48.363650Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T14:28:56.203Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.134.0.57",
                  "status": "affected",
                  "version": "11.120.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.41",
                  "status": "affected",
                  "version": "11.136.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.0.8",
                  "status": "affected",
                  "version": "11.138.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.57",
                  "status": "unaffected",
                  "version": "11.134.0.57",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.41",
                  "status": "unaffected",
                  "version": "11.136.0.41",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.0.8",
                  "status": "unaffected",
                  "version": "11.138.0.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Ali Mustafa (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T19:52:47.162Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43502940099991"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-68490",
        "datePublished": "2026-09-23T19:52:47.162Z",
        "dateReserved": "2026-07-30T15:00:00.609Z",
        "dateUpdated": "2026-09-24T14:28:56.203Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87900 (GCVE-0-2026-87900)

    Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-23 20:05
    VLAI
    Summary
    Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 20:05 UTC
    CWE
    • CWE-88 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
    Impacted products
    Vendor Product Version
    WebPros WP Toolkit for cPanel Affected: 0 , ≤ 6.11.2-10794 (semver)
    Unaffected: 6.11.3-10850 , < 6.11.3-10850 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87900",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T20:05:51.395539Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T20:05:57.710Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "WP Toolkit for cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThanOrEqual": "6.11.2-10794",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.11.3-10850",
                  "status": "unaffected",
                  "version": "6.11.3-10850",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ali Mustafa (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-88",
                  "description": "CWE-88 Improper Neutralization of Argument Delimiters in a Command (\u0027Argument Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T19:52:47.153Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43597969409943"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-87900",
        "datePublished": "2026-09-23T19:52:47.153Z",
        "dateReserved": "2026-09-09T15:00:00.574Z",
        "dateUpdated": "2026-09-23T20:05:57.710Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87898 (GCVE-0-2026-87898)

    Vulnerability from cvelistv5 – Published: 2026-09-23 19:52 – Updated: 2026-09-23 20:06
    VLAI
    Summary
    OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 20:06 UTC
    CWE
    • CWE-78 - OS Command Injection
    Impacted products
    Vendor Product Version
    WebPros Plesk extension "Site Import" Affected: 1.6.6 , ≤ 1.12.1 (semver)
    Unaffected: 1.12.2 , < 1.12.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87898",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T20:06:19.972843Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T20:06:28.175Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Plesk extension \"Site Import\"",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThanOrEqual": "1.12.1",
                  "status": "affected",
                  "version": "1.6.6",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.12.2",
                  "status": "unaffected",
                  "version": "1.12.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ali Mustafa (rz1027)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T19:52:47.081Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/43641151026583"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-87898",
        "datePublished": "2026-09-23T19:52:47.081Z",
        "dateReserved": "2026-09-09T15:00:00.573Z",
        "dateUpdated": "2026-09-23T20:06:28.175Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68491 (GCVE-0-2026-68491)

    Vulnerability from cvelistv5 – Published: 2026-09-15 20:59 – Updated: 2026-09-16 18:04
    VLAI
    Summary
    An insufficient check allowed for the overwrite of arbitrary files via a symlink.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:04 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    Impacted products
    Vendor Product Version
    Webpros SolusVM Affected: 0 , < 1.30.15 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68491",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:04:00.594086Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:04:11.685Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SolusVM",
              "vendor": "Webpros",
              "versions": [
                {
                  "lessThan": "1.30.15",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "RackNerd"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An insufficient check allowed for the overwrite of arbitrary files via a symlink."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-15T20:59:50.186Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://docs.solusvm.com/en/solusvm1/release-notes/stable-branch/v1.30/#13015"
            },
            {
              "url": "https://docs.solusvm.com/en/solusvm1/release-notes/mainline-branch/v1.30/#13015"
            },
            {
              "url": "https://support.solusvm.com/hc/en-us/articles/43503583489687-CVE-2026-68491-Vulnerability-in-SolusVM-1-allows-Guest-to-Host-privilege-escalation"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-68491",
        "datePublished": "2026-09-15T20:59:50.186Z",
        "dateReserved": "2026-07-30T15:00:00.609Z",
        "dateUpdated": "2026-09-16T18:04:11.685Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68489 (GCVE-0-2026-68489)

    Vulnerability from cvelistv5 – Published: 2026-09-14 20:53 – Updated: 2026-09-15 13:28
    VLAI
    Summary
    Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-15 13:28 UTC
    CWE
    • CWE-96 - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68489",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-15T13:28:42.978491Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T13:28:53.581Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk extension \"Ruby\"",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "1.6.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Plesk extension \"Node.js Toolkit\"",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "2.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "d1n4h"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Static Code Injection in Plesk extensions \"Ruby\" before 1.6.6 and \"Node.js Toolkit\" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-96",
                  "description": "CWE-96 Improper Neutralization of Directives in Statically Saved Code (\u0027Static Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T20:53:05.644Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/43473204617239"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-68489",
        "datePublished": "2026-09-14T20:53:05.644Z",
        "dateReserved": "2026-07-30T15:00:00.609Z",
        "dateUpdated": "2026-09-15T13:28:53.581Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-67399 (GCVE-0-2026-67399)

    Vulnerability from cvelistv5 – Published: 2026-09-14 20:53 – Updated: 2026-09-15 13:28
    VLAI
    Summary
    Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-15 13:28 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    WebPros WHMCS Affected: 9.0.0 , < 9.0.8 (semver)
    Affected: 8.0.0 , < 8.13.7 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-67399",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-15T13:28:16.542784Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T13:28:24.720Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WHMCS",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "9.0.8",
                  "status": "affected",
                  "version": "9.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.13.7",
                  "status": "affected",
                  "version": "8.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "azizk (@realazizk)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T20:53:05.620Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://help.whmcs.com/m/125386/l/2118034-cve-2026-67399-whmcs-security-update-2026-09-03"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-67399",
        "datePublished": "2026-09-14T20:53:05.620Z",
        "dateReserved": "2026-07-29T15:00:02.294Z",
        "dateUpdated": "2026-09-15T13:28:24.720Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-65639 (GCVE-0-2026-65639)

    Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:19
    VLAI
    Summary
    OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 18:19 UTC
    CWE
    • CWE-78 - OS Command Injection
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-65639",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T18:19:30.960257Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T18:19:47.504Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ConfigServer Security \u0026 Firewall",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "16.30",
                  "status": "affected",
                  "version": "2.15",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ConfigServer Security \u0026 Firewall",
              "vendor": "ConfigServer",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "affected",
                  "version": "2.15",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "OS command injection in the advanced-rule parser of ConfigServer Security \u0026 Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.\n\nThe vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security \u0026 Firewall (CSF) may also be affected and should be evaluated independently."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T16:24:52.871Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43387923160343-Security-CVE-2026-65639-CSF-Security-Release"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-65639",
        "datePublished": "2026-09-10T16:24:52.871Z",
        "dateReserved": "2026-07-22T15:00:06.103Z",
        "dateUpdated": "2026-09-10T18:19:47.504Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68487 (GCVE-0-2026-68487)

    Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:08
    VLAI
    Summary
    Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 18:08 UTC
    CWE
    • CWE-36 - Absolute Path Traversal
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , ≤ 18.0.80.6 (semver)
    Affected: 0 , ≤ 18.0.79.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68487",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T18:08:44.436403Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T18:08:51.400Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThanOrEqual": "18.0.80.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "18.0.79.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal in Plesk\u0027s Backup Manager causes arbitrary file write as root by an authenticated customer."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-36",
                  "description": "CWE-36 Absolute Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T16:24:52.847Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/43248841638551-Vulnerability-in-Plesk-s-Backup-Manager-unsigned-backup-header-allows-path-traversal"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-68487",
        "datePublished": "2026-09-10T16:24:52.847Z",
        "dateReserved": "2026-07-30T15:00:00.608Z",
        "dateUpdated": "2026-09-10T18:08:51.400Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-65638 (GCVE-0-2026-65638)

    Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:19
    VLAI
    Summary
    Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 18:19 UTC
    CWE
    • CWE-78 - OS Command Injection
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-65638",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T18:19:11.551770Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T18:19:18.373Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ConfigServer Security \u0026 Firewall",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "16.30",
                  "status": "affected",
                  "version": "14.00",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ConfigServer Security \u0026 Firewall",
              "vendor": "ConfigServer",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "affected",
                  "version": "14.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper escaping of a request URL in  ConfigServer Security \u0026 Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.\n\nThe vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security \u0026 Firewall (CSF) may also be affected and should be evaluated independently."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T16:24:52.785Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43387915588375-Security-CVE-2026-65638-CSF-Security-Release"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-65638",
        "datePublished": "2026-09-10T16:24:52.785Z",
        "dateReserved": "2026-07-22T15:00:06.103Z",
        "dateUpdated": "2026-09-10T18:19:18.373Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68488 (GCVE-0-2026-68488)

    Vulnerability from cvelistv5 – Published: 2026-09-10 16:24 – Updated: 2026-09-10 18:18
    VLAI
    Summary
    A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 18:18 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , ≤ 18.0.80.6 (semver)
    Affected: 0 , ≤ 18.0.79.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68488",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T18:18:44.361511Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T18:18:54.741Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThanOrEqual": "18.0.80.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "18.0.79.10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T16:24:52.781Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-68488",
        "datePublished": "2026-09-10T16:24:52.781Z",
        "dateReserved": "2026-07-30T15:00:00.609Z",
        "dateUpdated": "2026-09-10T18:18:54.741Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-67401 (GCVE-0-2026-67401)

    Vulnerability from cvelistv5 – Published: 2026-09-09 15:49 – Updated: 2026-09-10 03:56
    VLAI
    Summary
    A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros cPanel Affected: 0 , < 11.134.0.55 (semver)
    Affected: 0 , < 11.136.0.39 (semver)
    Affected: 0 , < 11.138.0.4 (semver)
    Affected: 0 , < 11.138.1.9 (semver)
    Affected: 0 , < 11.110.0.143 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-67401",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T03:56:49.614Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.134.0.55",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.39",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.0.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.1.9",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.110.0.143",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component"
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T15:49:40.391Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-67401",
        "datePublished": "2026-09-09T15:49:40.391Z",
        "dateReserved": "2026-07-29T15:00:02.294Z",
        "dateUpdated": "2026-09-10T03:56:49.614Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-67397 (GCVE-0-2026-67397)

    Vulnerability from cvelistv5 – Published: 2026-09-03 23:57 – Updated: 2026-09-04 19:47
    VLAI
    Summary
    Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-04 19:46 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , < 18.0.79.9 (semver)
    Affected: 18.0.80 , < 18.0.80.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-67397",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-04T19:46:57.842520Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T19:47:09.558Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.79.9",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "18.0.80.5",
                  "status": "affected",
                  "version": "18.0.80",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T23:57:15.922Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/43070000520855-Vulnerability-CVE-2026-67397-Arbitrary-code-execution-as-root-in-Plesk"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-67397",
        "datePublished": "2026-09-03T23:57:15.922Z",
        "dateReserved": "2026-07-29T15:00:02.293Z",
        "dateUpdated": "2026-09-04T19:47:09.558Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-67402 (GCVE-0-2026-67402)

    Vulnerability from cvelistv5 – Published: 2026-09-03 23:57 – Updated: 2026-09-04 19:47
    VLAI
    Summary
    An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-04 19:47 UTC
    CWE
    • CWE-552 - Files or Directories Accessible to External Parties
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-67402",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-04T19:47:27.442444Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T19:47:36.330Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ConfigServer Security \u0026 Firewall",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "16.31",
                  "status": "affected",
                  "version": "14.02",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ConfigServer Security \u0026 Firewall",
              "vendor": "ConfigServer",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "affected",
                  "version": "14.02",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An insecure Apache configuration in ConfigServer Security \u0026 Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-552",
                  "description": "CWE-552 Files or Directories Accessible to External Parties",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T23:57:15.878Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026"
            }
          ],
          "workarounds": [
            {
              "lang": "en",
              "value": "Disable Messenger v3 by setting MESSENGERV3 = \"0\" until version 16.31 can be installed. This is the shipped default."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-67402",
        "datePublished": "2026-09-03T23:57:15.878Z",
        "dateReserved": "2026-07-29T15:00:02.294Z",
        "dateUpdated": "2026-09-04T19:47:36.330Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-67398 (GCVE-0-2026-67398)

    Vulnerability from cvelistv5 – Published: 2026-09-03 23:57 – Updated: 2026-09-14 20:53
    VLAI
    Summary
    Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-04 19:47 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros WHMCS Affected: 4.5.0 , < 8.12.2 (semver)
    Affected: 8.13.0 , < 8.13.7 (semver)
    Affected: 9.0.0 , < 9.0.8 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-67398",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-04T19:47:54.274188Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T19:48:08.664Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WHMCS",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "8.12.2",
                  "status": "affected",
                  "version": "4.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.13.7",
                  "status": "affected",
                  "version": "8.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "9.0.8",
                  "status": "affected",
                  "version": "9.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "boomerang"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer\u0027s data via 2Checkout payment gateway\u0027s endpoint under specific conditions."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T20:53:05.678Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03"
            }
          ],
          "workarounds": [
            {
              "lang": "en",
              "value": "Deactivate 2Checkout payment gateway."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-67398",
        "datePublished": "2026-09-03T23:57:15.810Z",
        "dateReserved": "2026-07-29T15:00:02.294Z",
        "dateUpdated": "2026-09-14T20:53:05.678Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-65643 (GCVE-0-2026-65643)

    Vulnerability from cvelistv5 – Published: 2026-09-01 02:07 – Updated: 2026-09-02 03:55
    VLAI
    Summary
    Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-01 00:00 UTC
    CWE
    • CWE-95 - Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
    Impacted products
    Vendor Product Version
    WebPros cPanel Affected: 0 , < 11.110.0.141 (semver)
    Affected: 11.112.0.0 , < 11.134.0.53 (semver)
    Affected: 11.136.0.0 , < 11.136.0.37 (semver)
    Affected: 11.138.0.0 , < 11.138.0.2 (semver)
    Affected: 11.138.1.0 , < 11.138.1.7 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-65643",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-01T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T03:55:20.753Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.110.0.141",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.53",
                  "status": "affected",
                  "version": "11.112.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.37",
                  "status": "affected",
                  "version": "11.136.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.0.2",
                  "status": "affected",
                  "version": "11.138.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.138.1.7",
                  "status": "affected",
                  "version": "11.138.1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Ali Mustafa"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-95",
                  "description": "CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code (\u0027Eval Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-01T02:07:41.778Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Park-API-Vulnerability-August-27-2026"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-65643",
        "datePublished": "2026-09-01T02:07:41.778Z",
        "dateReserved": "2026-07-22T15:00:06.103Z",
        "dateUpdated": "2026-09-02T03:55:20.753Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-67394 (GCVE-0-2026-67394)

    Vulnerability from cvelistv5 – Published: 2026-09-01 02:07 – Updated: 2026-09-01 13:14
    VLAI
    Summary
    A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-01 13:14 UTC
    CWE
    • CWE-78 - OS Command Injection
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 18.0.34 , < 18.0.79.9 (semver)
    Affected: 18.0.80 , < 18.0.80.5 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-67394",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-01T13:14:29.944649Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-01T13:14:45.804Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.79.9",
                  "status": "affected",
                  "version": "18.0.34",
                  "versionType": "semver"
                },
                {
                  "lessThan": "18.0.80.5",
                  "status": "affected",
                  "version": "18.0.80",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Aziz Knani"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-01T02:07:41.777Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42968165026967-CVE-2026-67394-Vulnerability-in-Plesk-allows-privilege-escalation-to-root"
            }
          ],
          "workarounds": [
            {
              "lang": "en",
              "value": "Disable shell access for customers or resellers if it is not required (make sure their service plan does not allow to change it)"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-67394",
        "datePublished": "2026-09-01T02:07:41.777Z",
        "dateReserved": "2026-07-29T15:00:02.293Z",
        "dateUpdated": "2026-09-01T13:14:45.804Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-65646 (GCVE-0-2026-65646)

    Vulnerability from cvelistv5 – Published: 2026-08-26 21:21 – Updated: 2026-09-11 17:16
    VLAI
    Summary
    Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 13:01 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , < 18.0.79.11 (semver)
    Affected: 18.0.80 , < 18.0.80.7 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-65646",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T13:01:50.922762Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T15:04:11.031Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.79.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "18.0.80.7",
                  "status": "affected",
                  "version": "18.0.80",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Aziz Knani"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper neutralization of special elements in in Plesk\u0027s DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T17:16:03.698Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42877023875351-Vulnerability-CVE-2026-65646-in-Plesk-s-DNS-zone-management-functionality"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-65646",
        "datePublished": "2026-08-26T21:21:41.144Z",
        "dateReserved": "2026-07-22T15:00:06.104Z",
        "dateUpdated": "2026-09-11T17:16:03.698Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-65642 (GCVE-0-2026-65642)

    Vulnerability from cvelistv5 – Published: 2026-08-26 21:21 – Updated: 2026-08-27 18:07
    VLAI
    Summary
    Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 18:03 UTC
    CWE
    • CWE-639 - Insecure Direct Object Reference (IDOR)
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , ≤ 18.0.79.7 (semver)
    Affected: 18.0.80 , < 18.0.80.4 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-65642",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T18:03:28.894998Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T18:07:19.708Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThanOrEqual": "18.0.79.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "18.0.80.4",
                  "status": "affected",
                  "version": "18.0.80",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Aziz Knani"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers\u0027 databases."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Insecure Direct Object Reference (IDOR)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T21:21:41.122Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42844242102679-Vulnerability-CVE-2026-65642-in-Plesk-s-database-management-interface"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-65642",
        "datePublished": "2026-08-26T21:21:41.122Z",
        "dateReserved": "2026-07-22T15:00:06.103Z",
        "dateUpdated": "2026-08-27T18:07:19.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-65647 (GCVE-0-2026-65647)

    Vulnerability from cvelistv5 – Published: 2026-08-26 21:21 – Updated: 2026-08-27 17:59
    VLAI
    Summary
    Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 17:59 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    Impacted products
    Vendor Product Version
    WebPros Plesk Migrator Affected: 0 , < 2.36.0 (semver)
    Create a notification for this product.
    WebPros Plesk Site Import Affected: 0 , < 1.12.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-65647",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T17:59:40.758788Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T17:59:51.351Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk Migrator",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "2.36.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Plesk Site Import",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "1.12.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T21:21:41.033Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-65647",
        "datePublished": "2026-08-26T21:21:41.033Z",
        "dateReserved": "2026-07-22T15:00:06.104Z",
        "dateUpdated": "2026-08-27T17:59:51.351Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-64639 (GCVE-0-2026-64639)

    Vulnerability from cvelistv5 – Published: 2026-08-12 15:31 – Updated: 2026-08-14 18:29
    VLAI
    Summary
    Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-12 16:07 UTC
    CWE
    • CWE-266 - Incorrect Privilege Assignment
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 18.0.52 , < 18.0.79.6 (semver)
    Affected: 18.0.80.0 , < 18.0.80.2 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-64639",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-12T16:07:43.248382Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-14T18:29:23.333Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.79.6",
                  "status": "affected",
                  "version": "18.0.52",
                  "versionType": "semver"
                },
                {
                  "lessThan": "18.0.80.2",
                  "status": "affected",
                  "version": "18.0.80.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Aziz Knani"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266 Incorrect Privilege Assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T15:31:45.624Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42521305418903-Vulnerability-CVE-2026-64639-Privilege-Escalation-via-Database-Cloning-in-Plesk"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-64639",
        "datePublished": "2026-08-12T15:31:45.624Z",
        "dateReserved": "2026-07-20T15:00:00.697Z",
        "dateUpdated": "2026-08-14T18:29:23.333Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-64637 (GCVE-0-2026-64637)

    Vulnerability from cvelistv5 – Published: 2026-08-07 17:57 – Updated: 2026-08-07 18:25
    VLAI
    Summary
    Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 18:24 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , < 18.0.80.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-64637",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T18:24:11.245542Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T18:25:40.293Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.80.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-07T17:57:25.500Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42432168683799"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-64637",
        "datePublished": "2026-08-07T17:57:25.500Z",
        "dateReserved": "2026-07-20T15:00:00.696Z",
        "dateUpdated": "2026-08-07T18:25:40.293Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-64636 (GCVE-0-2026-64636)

    Vulnerability from cvelistv5 – Published: 2026-08-07 17:57 – Updated: 2026-08-07 18:23
    VLAI
    Summary
    An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 18:23 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 18.0.51 , < 18.0.80.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-64636",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T18:23:29.520962Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T18:23:52.542Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.80.1",
                  "status": "affected",
                  "version": "18.0.51",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-07T17:57:25.451Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42431868205079"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-64636",
        "datePublished": "2026-08-07T17:57:25.451Z",
        "dateReserved": "2026-07-20T15:00:00.696Z",
        "dateUpdated": "2026-08-07T18:23:52.542Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-58048 (GCVE-0-2026-58048)

    Vulnerability from cvelistv5 – Published: 2026-07-31 16:35 – Updated: 2026-08-07 18:00
    VLAI
    Summary
    Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-31 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros cPanel Affected: 0 , < 11.110.0.137 (semver)
    Affected: 0 , < 11.126.0.78 (semver)
    Affected: 0 , < 11.134.0.48 (semver)
    Affected: 0 , < 11.136.0.32 (semver)
    Affected: 0 , < 11.137.9999.99 (semver)
    Affected: 0 , < 11.118.0.71 (semver)
    Create a notification for this product.
    WebPros WP Squared Affected: 0 , < 11.138.1.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-58048",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-31T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-01T03:56:21.794Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.110.0.137",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.126.0.78",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.48",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.137.9999.99",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.118.0.71",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP Squared",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.138.1.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Vincent55 Yang"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper preservation of SQL mode when renaming databases in  cPanel allows execution of SQL in root context."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-07T18:00:28.533Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/42285745783703-CVE-2026-58048-Database-Privilege-Escalation"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/138-change-log"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-58048",
        "datePublished": "2026-07-31T16:35:56.665Z",
        "dateReserved": "2026-06-27T15:00:00.780Z",
        "dateUpdated": "2026-08-07T18:00:28.533Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-58047 (GCVE-0-2026-58047)

    Vulnerability from cvelistv5 – Published: 2026-07-31 16:35 – Updated: 2026-08-07 18:00
    VLAI
    Summary
    HTTP Smuggling in cPanel allows potential leak of credentials.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-31 17:17 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros cPanel Affected: 0 , < 11.110.0.137 (semver)
    Affected: 0 , < 11.126.0.78 (semver)
    Affected: 0 , < 11.134.0.48 (semver)
    Affected: 0 , < 11.136.0.32 (semver)
    Affected: 0 , < 11.137.9999.99 (semver)
    Affected: 0 , < 11.118.0.71 (semver)
    Create a notification for this product.
    WebPros WP Squared Affected: 0 , < 11.138.1.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-58047",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-31T17:17:29.381244Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-31T17:17:56.499Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "cPanel",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.110.0.137",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.126.0.78",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.134.0.48",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.136.0.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.137.9999.99",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "11.118.0.71",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WP Squared",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "11.138.1.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Vincent55 Yang"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "HTTP Smuggling in cPanel allows potential leak of credentials."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-444",
                  "description": "CWE-444 HTTP Request Smuggling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-07T18:00:48.776Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.cpanel.net/hc/en-us/articles/42285024734743-Security-CVE-2026-58047-HTTP-Request-Smuggling"
            },
            {
              "url": "https://docs.cpanel.net/changelogs/138-change-log"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-58047",
        "datePublished": "2026-07-31T16:35:56.600Z",
        "dateReserved": "2026-06-27T15:00:00.780Z",
        "dateUpdated": "2026-08-07T18:00:48.776Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-58046 (GCVE-0-2026-58046)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:02 – Updated: 2026-08-14 15:02
    VLAI
    Summary
    Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 12:38 UTC
    CWE
    Impacted products
    Vendor Product Version
    WebPros Plesk Affected: 0 , < 18.0.79.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-58046",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T12:38:10.851144Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T12:38:20.183Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Plesk",
              "vendor": "WebPros",
              "versions": [
                {
                  "lessThan": "18.0.79.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-14T15:02:39.515Z",
            "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
            "shortName": "hackerone"
          },
          "references": [
            {
              "url": "https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "assignerShortName": "hackerone",
        "cveId": "CVE-2026-58046",
        "datePublished": "2026-07-30T06:02:50.017Z",
        "dateReserved": "2026-06-27T15:00:00.780Z",
        "dateUpdated": "2026-08-14T15:02:39.515Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }