SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65646

CRITICAL · CVSS 9.9 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability in Plesk allows remote authenticated users to improperly access and disclose arbitrary local files, potentially leading to privilege escalation. This poses a significant risk to systems using Plesk, particularly for environments where user access is not tightly controlled. Organizations utilizing Plesk should prioritize remediation to mitigate the risk of unauthorized data exposure and privilege escalation.

CVE
CVE-2026-65646
Severity
CRITICAL
CVSS
9.9
EPSS
0.39%

Original NVD Description

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.