Situation
A security vulnerability CVE-2026-65646 was discovered in Plesk's DNS zone management functionality that could allow a customer with a DNS-managed domain to read arbitrary files from the server and obtain administrative credentials.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk for Linux | 18.0.79.7 and earlier 18.0.80 - 18.0.80.3 |
18.0.79.8 18.0.80.4 |
Impact
Unauthorized disclosure of server file contents is possible. A customer with an ordinary hosting subscription and a DNS-managed domain may be able to read files on the server that are not intended to be accessible to them.
This can lead to the disclosure of Plesk administrator and database credentials, which would give an attacker full control of the Plesk panel and access to all databases hosted on the server.
Servers where customers are permitted to manage DNS records for their own domains are affected.
Call to action
- The issue is fixed in Plesk 18.0.79.8 and 18.0.80.4.
- Update Plesk to apply the fix.
How to confirm the patched version is installed
After updating, verify that Plesk is running 18.0.79.8, 18.0.80.4, or later. See How to find version of Plesk installed on server for instructions.
Comments
Please sign in to leave a comment.