CyberRota Analysis
AI-GeneratedAn improper privilege management vulnerability in the XML-RPC API of Plesk versions prior to 18.0.80 allows authenticated resellers to escalate their privileges and gain administrative access to the root user account. This critical flaw poses a significant risk, as it could lead to unauthorized control over the server and its resources. Organizations using affected versions of Plesk should prioritize immediate updates to mitigate potential exploitation.
CVE
CVE-2026-64637
Severity
CRITICAL
CVSS
9.9
EPSS
0.26%
Original NVD Description
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.