Articles in this section

CVE-2026-64636 Vulnerability in Plesk: blind SQL injection

kb: security

Situation

A blind SQL injection vulnerability was discovered in Plesk.

Affected product version

Product Affected versions Patched versions
Plesk 18.0.51 - 18.0.80 18.0.80.1 and 18.0.79.5

Impact

An attacker could extract data from the server's database with a read-only SQL injection.

Call to action

Update Plesk to the latest build: How to update Plesk Obsidian to the latest build

Mitigation 

If you are unable to update immediately, you can reduce risk from this issue by either of the following:

  • Disabling OS-level system logins for resellers by setting systemAdmin = off under the [login] section of Panel.ini.
  • Disabling API access for reseller accounts via the relevant service plan permission.

We strongly recommend updating the latest hotfix version as soon as possible.

Please reach out to our support team if you have any questions or need further guidance.

Acknowledgement 

We would like to thank Aziz Knani for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

1 comment
Date Votes
  • Hi! Could you please clarify whether exploitation of this vulnerability requires an authenticated reseller account, or whether users with lower privileges (e.g. customer accounts) could also exploit it?

    The mitigation section seems to imply that reseller-level access is required, but this is not explicitly stated in the advisory.

    0

Please sign in to leave a comment.