Plesk Obsidian for Linux
Plesk Obsidian for Windows
kb: security
kb: ai-created
Situation
A security vulnerability CVE-2026-65642 was discovered in Plesk that could allow an authenticated user to gain unauthorized access to databases belonging to other users on the same server.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk for Linux | 18.0.79.7 and earlier 18.0.80 - 18.0.80.3 |
18.0.79.8 18.0.80.4 |
| Plesk for Windows | 18.0.79.7 and earlier 18.0.80 - 18.0.80.3 |
18.0.79.8 18.0.80.4 |
Impact
Unauthorized read and write access to other customers' databases is possible. This could allow an attacker to view, modify, or delete data belonging to other Plesk users on the same server.
Call to action
- The issue is fixed in Plesk 18.0.79.8 and 18.0.80.4.
- Update Plesk to apply the fix.
How to confirm the patched version is installed
After updating, verify that Plesk is running 18.0.79.8, 18.0.80.4, or later. See How to find version of Plesk installed on server for instructions.
Comments
Please sign in to leave a comment.