Articles in this section

Vulnerability CVE-2026-64639: Privilege Escalation via Database Cloning in Plesk

Plesk Obsidian for Linux Plesk Obsidian for Windows

Situation

A security vulnerability CVE-2026-64639 was found in Plesk's database cloning functionality that could lead to unauthorized database server administrator privileges.

Affected product versions

Product Affected versions Patched version
Plesk for Linux
  • 18.0.52-18.0.79.5
  • 18.0.80-18.0.80.1
  • 18.0.79.6
  • 18.0.80.2
Plesk for Windows
  • 18.0.52-18.0.79.5
  • 18.0.80-18.0.80.1
  • 18.0.79.6
  • 18.0.80.2

Impact

If this issue is left unaddressed, a customer who can clone or copy a database on the server could end up with database server administrator privileges. 

Call to action

Update Plesk to the latest build: How to update Plesk Obsidian to the latest build.

How to verify that a server is patched

Follow the steps from the How to find version of Plesk installed on server? If you are in version 18.0.79 Update #6 or version 18.0.80 Update #2, you are already patched for CVE-2026-64639.

Acknowledgements

We would like to thank Aziz Knani for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.