SQL Injection Vulnerability in Plesk Obsidian for Linux and Windows
CVE-2026-64636

7.7HIGH

Key Information:

Vendor

Webpros

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-64636?

An SQL injection vulnerability has been identified in Plesk Obsidian versions prior to 18.0.80 for both Linux and Windows platforms. This flaw enables an authenticated user to execute malicious queries, potentially leading to unauthorized access and extraction of sensitive data from the panel database. Users of affected versions are advised to apply necessary security patches and updates promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

Plesk 18.0.51 < 18.0.80.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.