Articles in this section

Vulnerability CVE-2026-64639: Privilege Escalation via Database Cloning in Plesk

Plesk Obsidian for Linux Plesk Obsidian for Windows

Situation

A security vulnerability CVE-2026-64639 was found in Plesk's database cloning functionality that could lead to unauthorized database server administrator privileges.

Affected product versions

Product Affected versions Patched version
Plesk for Linux
  • 18.0.52-18.0.79.5
  • 18.0.80-18.0.80.1
  • 18.0.79.6
  • 18.0.80.2
Plesk for Windows
  • 18.0.52-18.0.79.5
  • 18.0.80-18.0.80.1
  • 18.0.79.6
  • 18.0.80.2

Impact

If this issue is left unaddressed, a customer who can clone or copy a database on the server could end up with database server administrator privileges. 

Call to action

Update Plesk to the latest build: How to update Plesk Obsidian to the latest build.

How to verify that a server is patched

Follow the steps from the How to find version of Plesk installed on server? If you are in version 18.0.79 Update #6 or version 18.0.80 Update #2, you are already patched for CVE-2026-64639.

Acknowledgements

We would like to thank Aziz Knani for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

1 comment
Date Votes
  • Thank you for sharing this critical security advisory. Privilege escalation flaws like this are high priority, especially in multi-tenant shared hosting environments where a single compromised customer or reseller account could threaten every database on the server.For admins needing a temporary workaround before applying updates, disabling database cloning in client/reseller role permissions or restricting panel access via IP allowlisting can mitigate risk until the patch is applied. Be sure to check server logs for unexpected clone events or newly created DB admin users to rule out prior exploitation.

    0

Please sign in to leave a comment.