ZeroHour

CVE-2026-65642

large

Authenticated IDOR in WebPros Plesk exposes other customers' databases

CVSS 4.0
8.6 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-65642 is an insecure direct object reference (IDOR, CWE-639) in Plesk, the WebPros hosting control panel, affecting versions 18.0.79.7 and earlier as well as 18.0.80 through 18.0.80.3. A remote user with a valid account on the server can reference a database identifier belonging to a different customer without an ownership check, because the application fails to verify that the requested object belongs to the requesting user. This lets the attacker read and modify other customers' databases on a shared Plesk server, giving high confidentiality and integrity impact but no availability impact (CVSS 4.0: 8.6 High). Exposure is concentrated in multi-tenant hosting environments, where hosting providers and agencies run one Plesk server for many customer accounts; single-tenant deployments have little to lose from this flaw. As of now there is no public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days, so exploitation has not been observed.

What to do: Upgrade Plesk to a release newer than 18.0.80.3 (consult WebPros advisory AV26-854 for the exact fixed build). Until patched, limit which subscriber accounts can manage databases, check access logs for signs of cross-customer database reads or writes, and ensure customers use least-privilege database credentials. Prioritize patching servers that host many third-party customers, since exploitation requires an authenticated account on a shared instance.

Affected
WebPros Plesk18.0.79.7 and earlier; 18.0.80 through 18.0.80.3
Estimated exposure
largetens of thousands of internet-exposed Plesk servers, plausibly hundreds of thousands of hosted customer accounts — Plesk is a mainstream commercial hosting control panel widely deployed at shared-hosting providers, and public internet scans and deployment patterns put the installed base in the tens of thousands of (typically multi-tenant) servers, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

Weakness
CWE-639
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

WebPros security advisory (AV26-854)

Canadian Centre for Cyber Security relayed a WebPros advisory covering Plesk vulnerabilities CVE-2026-65642 and CVE-2026-65647 with fixed versions released.

WebPros released a security advisory affecting Plesk versions prior to 18.0.79.8 and 18.0.80.4, Plesk Migrator prior to 2.36.0, and Plesk Site Import prior to 1.12.1. The listed vulnerabilities are CVE-2026-65642 in Plesk's database management interface and CVE-2026-65647 in the Site Import and Migrator extensions. The Canadian Centre for Cyber Security (AV26-854) encourages users and administrators to apply the available updates.