CVE-2026-65642
8.6WebPros · Plesk
A vulnerability in the Plesk database management interface allows authenticated users to perform unauthorized read and write operations on databases belonging to other customers.
Executive summary
A high-severity insecure direct object reference vulnerability in Plesk allows remote authenticated users to compromise the integrity and confidentiality of other customers' databases.
Vulnerability
This is an insecure direct object reference (CWE-639) flaw within the Plesk database management interface. The vulnerability permits a remote authenticated user to manipulate database objects belonging to other tenants without proper authorization.
Business impact
The exploitation of this vulnerability poses a significant risk to data confidentiality and integrity, as unauthorized actors can access or modify sensitive information stored in other customers' databases. Given the CVSS score of 8.6, this flaw is categorized as high severity and requires immediate attention to prevent potential data breaches or service disruption. Failure to remediate this issue could lead to severe reputational damage and loss of trust for hosting providers.
Remediation
Immediate Action: Update Plesk to version 18.0.79.8 or 18.0.80.4 or later immediately to resolve the vulnerable code path.
Proactive Monitoring: Review web access and database management logs for unusual query patterns or unauthorized attempts to access database objects associated with different user accounts.
Compensating Controls: While no direct virtual patch is available, restricting access to the Plesk management interface to trusted IP addresses or internal networks can minimize the attack surface until the update is applied.
Exploitation status
Public Exploit Available: No (exploit_available is false).
Analyst recommendation
This vulnerability represents a critical risk to multi-tenant environments where database isolation is essential. Security teams must prioritize patching the Plesk installation to the specified secure versions immediately. Given the potential for unauthorized data modification, administrators should also conduct an audit of database access logs following the update to ensure no unauthorized activity occurred prior to remediation.
More WebPros CVEs
Sources
Originally found and disclosed by Aziz Knani, per the CVE Program record.