CVE-2026-64636
WebPros · Plesk
An SQL injection vulnerability exists in Plesk Obsidian, potentially allowing an authenticated user to perform unauthorized database operations.
Executive summary
A high-severity SQL injection vulnerability in Plesk Obsidian allows authenticated users to execute unauthorized database queries, threatening the integrity of the hosting environment.
Vulnerability
This SQL injection vulnerability allows an authenticated attacker to manipulate database queries. The vulnerability is restricted to authenticated users with low privileges, yet the potential impact on the underlying database is significant.
Business impact
SQL injection poses a severe threat to data confidentiality and integrity, as it can allow unauthorized users to extract sensitive information or modify database contents. With a CVSS score of 7.7, this vulnerability poses a high risk to the security of hosted websites and the management infrastructure of the Plesk environment.
Remediation
Immediate Action: Update Plesk Obsidian to version 18.0.80.1 or later to remediate the SQL injection flaw.
Proactive Monitoring: Enable database query logging to detect anomalous or unauthorized SQL statements and review access logs for signs of attempted exploitation.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the risk of unauthorized database access, applying the vendor patch is the only effective way to fully address this vulnerability. Administrators should prioritize this update to ensure the continued security of the Plesk platform and all hosted data.