Description
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
Published: 2026-08-12
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an incorrect database cloning process in Plesk versions prior to 18.0.79.6 and 18.0.80.2. This flaw permits a user with low privileges, such as a customer or reseller, to execute arbitrary code on the system under the identity of the database server administrator. The weakness corresponds to CWE‑266, and the potential impact includes full privilege escalation and remote code execution that could compromise the entire hosting environment.

Affected Systems

Affected by this issue are WebPros Plesk installations running versions 18.0.52 up to (but not including) 18.0.79.6 and 18.0.80.2—that is, 18.0.52 through 18.0.79.5 and 18.0.80.1. All users with access to the Plesk control panel in these editions are at risk until the vulnerability is remediated.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity, and while the EPSS score is not available, the high score suggests that exploitation is realistic. Based on the description, it is inferred that the exploit can be performed remotely through the Plesk web interface, exploiting the database cloning feature that is currently unrestricted for low‑privileged users. The vulnerability has not been listed in the CISA KEV catalog, but its high impact warrants immediate attention.

Generated by OpenCVE AI on August 13, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Plesk to a version that includes the fix, such as 18.0.79.6 or later.
  • Restrict database cloning permissions so that only trusted administrators can perform cloning operations.
  • Verify that no unauthorized database cloning activity is occurring by monitoring Plesk logs and database access logs.

Generated by OpenCVE AI on August 13, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unrestricted Database Cloning in Plesk 18

Wed, 12 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros plesk
Vendors & Products Webpros
Webpros plesk

Wed, 12 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
Weaknesses CWE-266
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-14T18:29:23.333Z

Reserved: 2026-07-20T15:00:00.697Z

Link: CVE-2026-64639

cve-icon Vulnrichment

Updated: 2026-08-12T16:07:50.867Z

cve-icon NVD

Status : Received

Published: 2026-08-12T16:17:12.280

Modified: 2026-08-14T19:17:46.777

Link: CVE-2026-64639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment