CVE-2026-65646
8.7WebPros · Plesk
A vulnerability in Plesk allows remote authenticated users to disclose arbitrary local files and escalate their privileges through improper neutralization of special elements in the DNS management module.
Executive summary
A critical vulnerability in WebPros Plesk allows authenticated remote attackers to read sensitive local files and achieve privilege escalation, posing a significant risk to server integrity.
Vulnerability
This flaw is caused by CWE-74, which is improper neutralization of special elements in the DNS zone management functionality. The vulnerability requires the attacker to have an authenticated user account to trigger the exploit, which then leads to arbitrary file disclosure and privilege escalation.
Business impact
The ability for an authenticated user to read arbitrary local files and escalate privileges can lead to a complete compromise of the Plesk management environment. Given the high CVSS score of 8.7, this vulnerability represents a significant threat to data confidentiality and system-wide administrative control, potentially allowing attackers to pivot into other hosted applications or system services.
Remediation
Immediate Action: Administrators must update Plesk to version 18.0.79.8 or 18.0.80.4, or newer, to address the underlying injection flaw.
Proactive Monitoring: Review web server access logs for anomalous requests directed at the DNS zone management interface, particularly those containing unexpected special characters or directory traversal patterns.
Compensating Controls: Implement strict access control policies for the Plesk control panel to ensure only trusted users have access, and utilize a Web Application Firewall to filter malicious input strings if immediate patching is delayed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention, as it provides a clear path for authenticated users to gain elevated control over the hosting environment. Organizations should prioritize patching their Plesk installations during the next maintenance window to prevent potential exploitation of this high-risk injection flaw.
More WebPros CVEs
Sources
Originally found and disclosed by Aziz Knani, per the CVE Program record.