Articles in this section

Vulnerability CVE-2026-65646 in Plesk's DNS zone management functionality

Plesk Obsidian for Linux kb: security kb: ai-created

Situation

A security vulnerability CVE-2026-65646 was discovered in Plesk's DNS zone management functionality that could allow a customer with a DNS-managed domain to read arbitrary files from the server and obtain administrative credentials.

Affected product version

Product Affected versions Patched versions
Plesk for Linux 18.0.79.7 and earlier
18.0.80 - 18.0.80.3
18.0.79.8
18.0.80.4

Impact

Unauthorized disclosure of server file contents is possible. A customer with an ordinary hosting subscription and a DNS-managed domain may be able to read files on the server that are not intended to be accessible to them.

This can lead to the disclosure of Plesk administrator and database credentials, which would give an attacker full control of the Plesk panel and access to all databases hosted on the server.

Servers where customers are permitted to manage DNS records for their own domains are affected.

Call to action

  1. The issue is fixed in Plesk 18.0.79.8 and 18.0.80.4.
  2. Update Plesk to apply the fix.

How to confirm the patched version is installed

After updating, verify that Plesk is running 18.0.79.8, 18.0.80.4, or later. See How to find version of Plesk installed on server for instructions.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.