Articles in this section

CVE-2026-64637 Authentication Bypass Leading to Privilege Escalation in Plesk

kb: security

Situation

A security vulnerability was discovered in Plesk that allows an authentication bypass, resulting in privilege escalation from a Reseller-level account to root.

Affected product version

Product Affected versions Patched versions
Plesk for Linux 18.0.80 and earlier 18.0.80.1 and 18.0.79.5
Plesk for Windows 18.0.80 and earlier 18.0.80.1 and 18.0.79.5

How to verify that a server is patched

You can confirm your installed Plesk version and build using the Plesk interface:

  1. Log in to Plesk.
  2. In the left sidebar, go to Tools & Settings.
  3. Under Plesk, click About Plesk.
  4. The currently installed Plesk version is displayed under the logo (for example, "Version 18.0.79 Update #5").


     
  5. Compare the displayed build to the patched version in the table above. If an earlier version is shown, the server should be updated.

Impact

An attacker with Reseller-level access could gain full root-level control of the server.

Call to action

Update Plesk to the latest build: How to update Plesk Obsidian to the latest build

Mitigation 

If you are unable to update immediately, you can reduce risk from this issue by either of the following:

  • Disabling OS-level system logins for resellers by setting systemAdmin = off under the [login] section of Panel.ini.
  • Disabling API access for reseller accounts via the relevant service plan permission.

We strongly recommend updating the latest hotfix version as soon as possible.

Please reach out to our support team if you have any questions or need further guidance.

Acknowledgement 

We would like to thank Aziz Knani for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

2 comments
Date Votes
  • Ik am getting tired of these CVEs lately. Plesk becoming unreliable.

    0
  • The sub-version patch releases, while not mirroring that to /usr/local/psa/version, is really annoying.  The static file can be easily cataloged by unprivileged monitoring agents.  It isn't acceptable to need to run a root command (plesk version) just to see if a patch is present.

    1

Please sign in to leave a comment.