Plesk Obsidian for Linux
Plesk Obsidian for Windows
Situation
A security vulnerability CVE-2026-64639 was found in Plesk's database cloning functionality that could lead to unauthorized database server administrator privileges.
Affected product versions
| Product | Affected versions | Patched version |
|---|---|---|
| Plesk for Linux |
|
|
| Plesk for Windows |
|
|
Impact
If this issue is left unaddressed, a customer who can clone or copy a database on the server could end up with database server administrator privileges.
Call to action
Update Plesk to the latest build: How to update Plesk Obsidian to the latest build.
How to verify that a server is patched
Follow the steps from the How to find version of Plesk installed on server?
Acknowledgements
We would like to thank Aziz Knani for responsibly disclosing this vulnerability.
Comments
Please sign in to leave a comment.