AI analysis
CVE-2026-65642 is an insecure direct object reference (IDOR, CWE-639) in Plesk, the WebPros hosting control panel, affecting versions 18.0.79.7 and earlier as well as 18.0.80 through 18.0.80.3. A remote user with a valid account on the server can reference a database identifier belonging to a different customer without an ownership check, because the application fails to verify that the requested object belongs to the requesting user. This lets the attacker read and modify other customers' databases on a shared Plesk server, giving high confidentiality and integrity impact but no availability impact (CVSS 4.0: 8.6 High). Exposure is concentrated in multi-tenant hosting environments, where hosting providers and agencies run one Plesk server for many customer accounts; single-tenant deployments have little to lose from this flaw. As of now there is no public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days, so exploitation has not been observed.
What to do: Upgrade Plesk to a release newer than 18.0.80.3 (consult WebPros advisory AV26-854 for the exact fixed build). Until patched, limit which subscriber accounts can manage databases, check access logs for signs of cross-customer database reads or writes, and ensure customers use least-privilege database credentials. Prioritize patching servers that host many third-party customers, since exploitation requires an authenticated account on a shared instance.
Affected
| WebPros Plesk | 18.0.79.7 and earlier; 18.0.80 through 18.0.80.3 |
Estimated exposure
largetens of thousands of internet-exposed Plesk servers, plausibly hundreds of thousands of hosted customer accounts — Plesk is a mainstream commercial hosting control panel widely deployed at shared-hosting providers, and public internet scans and deployment patterns put the installed base in the tens of thousands of (typically multi-tenant) servers, so…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.