CVE-2026-64637 Details
Description
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
A vulnerability in the XML-RPC API of Plesk, affecting versions prior to 18.0.80, allows authenticated resellers to gain administrative access to the root user account. This issue arises from improper privilege management, enabling a reseller-level account to bypass authentication and escalate privileges to root.
Users are advised to update Plesk to version 18.0.80.1 or 18.0.79.5. If an immediate update is not possible, resellers can disable OS-level system logins by modifying the 'Panel.ini' file or disable API access for reseller accounts through the relevant service plan permission.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.plesk.com/hc/en-us/articles/42432168683799 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |