AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-64639

CRITICAL · CVSS 9.3 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A critical vulnerability in Plesk versions prior to 18.0.79.6 and 18.0.80.2 allows low-privileged users, such as customers or resellers, to exploit an incorrect database cloning process, enabling them to execute arbitrary code with the privileges of the database server administrator. This poses a significant risk of unauthorized access and potential data compromise. Organizations using affected versions should prioritize immediate patching to mitigate this severe security threat.

CVE
CVE-2026-64639
Severity
CRITICAL
CVSS
9.3
EPSS
0.30%

Original NVD Description

Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.