Privilege Escalation Vulnerability in Plesk by Plesk
CVE-2026-64639

9.3CRITICAL

Key Information:

Vendor

Webpros

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-64639?

A security flaw in the database cloning process of Plesk versions 18.0.52 prior to 18.0.79.6 and 18.0.80.2 permits low-privileged users, such as customers or resellers, to execute arbitrary code with the permissions of the database server administrator. This vulnerability can potentially compromise the integrity and security of the database management system, enabling unauthorized actions that could affect other hosted services.

Affected Version(s)

Plesk 18.0.52 < 18.0.79.6

Plesk 18.0.80.0 < 18.0.80.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aziz Knani
.