High SEVERITY — Vulnerability

CVE-2026-64636 — An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

Platform
Plesk
CVE Record
CVE-2026-64636
CVSS Score
7.7/10
Published
07 August 2026
Views
31
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

Assessment

  • CVE: CVE-2026-64636
  • CVSS base score: 7.7
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

Plesk — Related Advisories

VIEW ALL →