Warning: Privilege Escalation in Plesk, Patch Immediately!
CVE/CVSS: CVE-2026-64639: 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Plesk is a widely used hosting automation and server management platform that provides customers with functionality for managing websites, databases, email, domains, and other hosting services. CVE-2026-64639 is an authorization vulnerability affecting database management functionality. A customer who has permission to clone or copy a database on the server may be able to abuse this functionality to obtain database server administrator privileges.
The impact to confidentiality, integrity, and availability is high .
This weakness is particularly significant in multi-tenant hosting environments where customers are intentionally restricted to their own databases. Exploitation could allow a lower-privileged customer to escape these intended database-level boundaries and obtain administrative control over the underlying database server.
There is no evidence of exploitation of this vulnerability in the wild.
This weakness allows attackers to conduct the following:
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via .
While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
