An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.plesk.com/hc/en-us/articles/42431868205079 |
|
History
Fri, 07 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated SQL Injection Allowing Arbitrary Database Read in Plesk Obsidian | |
| First Time appeared |
Webpros
Webpros plesk |
|
| Vendors & Products |
Webpros
Webpros plesk |
Fri, 07 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Fri, 07 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-08-07T18:23:52.542Z
Reserved: 2026-07-20T15:00:00.696Z
Link: CVE-2026-64636
Updated: 2026-08-07T18:23:48.209Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T20:00:05Z