High SEVERITY — Vulnerability

CVE-2026-65646 — Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Platform
Plesk
CVE Record
CVE-2026-65646
CVSS Score
8.7/10
Published
26 August 2026
Views
26
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Assessment

  • CVE: CVE-2026-65646
  • CVSS base score: 8.7
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

Plesk — Related Advisories

VIEW ALL →