AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-64637

CRITICAL · CVSS 9.9 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An improper privilege management vulnerability in the XML-RPC API of Plesk versions prior to 18.0.80 allows authenticated resellers to escalate their privileges and gain administrative access to the root user account. This critical flaw poses a significant risk, as it could lead to unauthorized control over the server and its resources. Organizations using affected versions of Plesk should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-64637
Severity
CRITICAL
CVSS
9.9
EPSS
0.26%

Original NVD Description

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.