Critical SEVERITY — Vulnerability

CVE-2025-66430 — Plesk 18.0 has Incorrect Access Control.

Plesk 18.0 has Incorrect Access Control.

Platform
Plesk
CVE Record
CVE-2025-66430
CVSS Score
9.1/10
Published
12 December 2025
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Summary

Plesk 18.0 has Incorrect Access Control.

Assessment

  • CVE: CVE-2025-66430
  • CVSS base score: 9.1
  • Vector: CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N
  • Source: [NVD entry](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-66430)

References

  • [docs.plesk.com](https:\/\/docs.plesk.com\/release-notes\/obsidian\/whats-new\/)
  • [support.plesk.com](https:\/\/support.plesk.com\/hc\/en-us\/articles\/36261922405015--CVE-2025-66430-Security-vulnerability-in-Password-Protected-Directories-allows-Plesk-users-to-gain-root-level-access-to-a-Plesk-server)

Actions

  • Verify affected systems in the inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until the patch is applied
plesk *

Plesk — Related Advisories

VIEW ALL →