Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros plesk |
|
| Vendors & Products |
Webpros
Webpros plesk |
Fri, 29 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XPath Injection in Plesk APS Catalog Enables Local Privilege Escalation |
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation. | |
| Weaknesses | CWE-643 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-05-29T16:43:18.000Z
Reserved: 2026-05-08T15:00:02.447Z
Link: CVE-2026-44962
Updated: 2026-05-29T16:43:14.744Z
Status : Awaiting Analysis
Published: 2026-05-29T16:16:27.567
Modified: 2026-05-29T16:33:43.467
Link: CVE-2026-44962
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:18:33Z