Call us: 0300 131 9608

Plesk Security Vulnerability: CVE-2026-58046 Tuesday 28th July 2026 09:38:00


Plesk has released a security update addressing CVE-2026-58046, a vulnerability affecting the Plesk XML-RPC API.

The vulnerability affects Plesk versions below 18.0.79.4 and could allow an authenticated Plesk customer or reseller account to access information held within the Plesk database.

Our teams are applying the required update to servers covered by our managed service.

Customers operating self-managed Plesk servers should update to Plesk version 18.0.79.4 or later as soon as possible. This can be completed through Tools & Settings > Updates and Upgrades within Plesk.

Customers who are unable to apply the update should restrict or disable access to the Plesk XML API until the update can be installed.

Further information on this can be found at: https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API