CVE-2026-64636: SQL Injection
Published Aug 7, 2026
·Updated
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Affected Software
1 affected component
Plesk Plesk Obsidian<=18.0.80
Event History
Aug 7, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64636?
The severity of CVE-2026-64636 is high, with a score of 7.7.
2
How do I fix CVE-2026-64636?
To fix CVE-2026-64636, update Plesk Obsidian to the latest version beyond 18.0.80.
3
Who is affected by CVE-2026-64636?
CVE-2026-64636 affects authenticated users of Plesk Obsidian versions up to 18.0.80 on both Linux and Windows platforms.
4
What kind of attack can be executed due to CVE-2026-64636?
CVE-2026-64636 allows an authenticated user to perform SQL injection attacks and read arbitrary data from the Plesk panel database.
5
Is there a workaround for CVE-2026-64636?
Currently, the best mitigation for CVE-2026-64636 is to upgrade to a patched version of Plesk Obsidian.