Description
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
Published: 2026-08-26
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure direct object reference exists in the Plesk database management interface. The flaw permits any remote user that has authenticated to the Plesk control panel to read or modify databases belonging to other customers. The result is a confidentiality breach and potential data loss for those other customers. The weakness is categorized as CWE‑639.

Affected Systems

Plesk by WebPros – specifically versions 18.0.79.7 and earlier, and the release series 18.0.80 through 18.0.80.3 are vulnerable. Systems running these releases are at risk if the database management interface is exposed to remote users.

Risk and Exploitability

The CVSS score of 8.6 marks this vulnerability as high severity. The EPSS score is not available, but the lack of a KEV listing does not diminish the risk; the flaw can be exploited by any authenticated Plesk user over the network. If an attacker has credentials for a customer account, they can target other customers’ databases directly, leading to unauthorized disclosure or alteration. "

Generated by OpenCVE AI on August 26, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Plesk to a non‑affected release, such as 18.0.81 or later.
  • If an immediate upgrade is not possible, restrict the database management interface to a narrow set of privileged users or disable it for external access, ensuring that each account can only view and edit its own databases.
  • Place the Plesk control panel behind a secure, internal network segment and limit external exposure to authenticated management traffic only.
  • Enable logging and monitoring of database queries from the Plesk interface to detect anomalous or cross‑customer access attempts.

Generated by OpenCVE AI on August 26, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Database Access via Insecure Direct Object Reference in Plesk
First Time appeared Webpros
Webpros plesk
Vendors & Products Webpros
Webpros plesk

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-26T21:21:41.122Z

Reserved: 2026-07-22T15:00:06.103Z

Link: CVE-2026-65642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T22:16:25.883

Modified: 2026-08-26T22:16:25.883

Link: CVE-2026-65642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:30:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key