Articles in this section

Vulnerability CVE-2026-65642 in Plesk's database management interface

Plesk Obsidian for Linux Plesk Obsidian for Windows kb: security kb: ai-created

Situation

A security vulnerability CVE-2026-65642 was discovered in Plesk that could allow an authenticated user to gain unauthorized access to databases belonging to other users on the same server.

Affected product version

Product Affected versions Patched versions
Plesk for Linux 18.0.79.7 and earlier
18.0.80 - 18.0.80.3
18.0.79.8
18.0.80.4
Plesk for Windows 18.0.79.7 and earlier
18.0.80 - 18.0.80.3
18.0.79.8
18.0.80.4

Impact

Unauthorized read and write access to other customers' databases is possible. This could allow an attacker to view, modify, or delete data belonging to other Plesk users on the same server.

Call to action

  1. The issue is fixed in Plesk 18.0.79.8 and 18.0.80.4.
  2. Update Plesk to apply the fix.

How to confirm the patched version is installed

After updating, verify that Plesk is running 18.0.79.8, 18.0.80.4, or later. See How to find version of Plesk installed on server for instructions.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.