Articles in this section

CVE-2026-64636 Vulnerability in Plesk: blind SQL injection

kb: security

Situation

A blind SQL injection vulnerability was discovered in Plesk.

Affected product version

Product Affected versions Patched versions
Plesk for Linux 18.0.51 - 18.0.79.4
18.0.80
18.0.79.5
18.0.80.1
Plesk for Windows 18.0.79.4 and earlier
18.0.80
18.0.79.5
18.0.80.1

How to verify that a server is patched

You can confirm your installed Plesk version and build using the Plesk interface:

  1. Log in to Plesk.
  2. In the left sidebar, go to Tools & Settings.
  3. Under Plesk, click About Plesk.
  4. The currently installed Plesk version is displayed under the logo (for example, "Version 18.0.80 Update #1").
     

    1946.png

     

  5. Compare the displayed build to the patched version in the table above. If an earlier version is shown, the server should be updated.

Impact

An attacker could extract data from the server's database with a read-only SQL injection.

Call to action

Update Plesk to the latest build: How to update Plesk Obsidian to the latest build

Acknowledgement 

We would like to thank Aziz Knani for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

7 comments
Date Votes
  • Hi! Could you please clarify whether exploitation of this vulnerability requires an authenticated reseller account, or whether users with lower privileges (e.g. customer accounts) could also exploit it?

    The mitigation section seems to imply that reseller-level access is required, but this is not explicitly stated in the advisory.

    0
  • We would also like to know the answer to Amalfiweb 's question!

    0
  • Websavers Inc Amalfiweb The security team specified resellers in the mitigation, so it's for resellers, but to fully address this Plesk should be updated. 

    1
  • Hello, I cannot login to my Plesk account due to this issue.

    0
  • DAVID WHITE This shouldn't cause any issues with login. Please open a ticket with us if you need assistance with logging in.

    0
  • I did open a ticket at approx. 15:00 EST but it is not showing up in ‘My Request’

    0
  • Websavers Inc Amalfiweb The security team sent us an update clarifying that it is not specific to reseller accounts. Plesk should be updated to address this issue.

    1

Please sign in to leave a comment.