CVE-2026-64639: Plesk Plesk vulnerability
Published Aug 12, 2026
·Updated
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
Affected Software
1 affected component
Plesk Plesk>18.0.52<=18.0.79.6, >18.0.52<=18.0.80.2
Event History
Aug 12, 2026
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-64639?
CVE-2026-64639 has a risk rating of 68 indicating a moderate level of severity.
2
How do I fix CVE-2026-64639?
To fix CVE-2026-64639, upgrade to Plesk version 18.0.79.6 or 18.0.80.2 or newer.
3
Who is affected by CVE-2026-64639?
CVE-2026-64639 affects low-privileged users such as customers and resellers of Plesk.
4
What type of vulnerability is CVE-2026-64639?
CVE-2026-64639 is a privilege escalation vulnerability that allows arbitrary code execution.
5
When was CVE-2026-64639 published?
CVE-2026-64639 was published on August 12, 2026.