Critical Privilege Escalation Vulnerability in Plesk Requires Immediate Action
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A severe privilege escalation vulnerability, CVE-2026-64639, has been identified in Plesk versions prior to 18.0.79.6 and 18.0.80.2. This flaw allows low-privileged users to execute arbitrary code as the database server administrator, significantly impacting multi-tenant hosting environments. The vulnerability was published on August 12, 2026, and has a CVSS score of 9.3, indicating a high severity level. While there is currently no evidence of exploitation in the wild, the Centre for Cybersecurity Belgium has issued an urgent recommendation for affected organizations to apply patches immediately. The vulnerability affects users who can clone or copy databases, potentially allowing them to breach intended security boundaries. Organizations are advised to enhance monitoring and detection capabilities to identify any suspicious activity related to this vulnerability.
Key Points: • CVE-2026-64639 allows low-privileged users to escalate privileges on Plesk servers. • The vulnerability has a high CVSS score of 9.3, indicating critical risk. • Immediate patching is recommended as there is currently no known exploitation.