CVE-2026-64637: Critical severity Plesk Plesk vulnerability
Published Aug 7, 2026
·Updated
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
Affected Software
1 affected component
Plesk Plesk<18.0.80
Event History
Aug 7, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-64637?
The severity of CVE-2026-64637 is critical, with a CVSS score of 9.9.
2
How do I fix CVE-2026-64637?
To fix CVE-2026-64637, upgrade Plesk to version 18.0.80 or later.
3
What systems are affected by CVE-2026-64637?
CVE-2026-64637 affects Plesk versions prior to 18.0.80.
4
What does CVE-2026-64637 exploit?
CVE-2026-64637 exploits improper privilege management in the XML-RPC API.
5
Who is primarily affected by CVE-2026-64637?
Authenticated resellers using Plesk can be affected by CVE-2026-64637, as it allows them to obtain administrative access.