Insecure Direct Object Reference in Plesk Database Management Interface
CVE-2026-65642

8.6HIGH

Key Information:

Vendor

Webpros

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-65642?

A vulnerability exists in the Plesk database management interface that allows remote authenticated users to exploit insecure direct object references. This flaw enables unauthorized individuals to access and modify databases belonging to other customers. It presents a significant risk to data integrity and confidentiality in hosting environments where multiple users share resources, underscoring the need for enhanced security protocols and user access management.

Affected Version(s)

Plesk 0 <= 18.0.79.7

Plesk 18.0.80 < 18.0.80.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aziz Knani
.