What is CVE-2026-64636?
CVE-2026-64636 is an SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows that allows an authenticated user to read arbitrary data from the panel database. Updating Plesk to the latest version is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-64636 Plesk Obsidian 18.0.80 və əvvəlki versiyalarda autentifikasiya olunmuş istifadəçiyə panel verilənlər bazasından ixtiyari məlumatları oxumağa imkan verən SQL injection zəifliyidir. Bu, həm Linux, həm də Windows platformalarına təsir edir. Plesk-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What versions of Plesk are affected by CVE-2026-64636?
CVE-2026-64636 affects Plesk Obsidian up to version 18.0.80.
Does CVE-2026-64636 require authentication to be exploited?
Yes, this SQL injection vulnerability requires an authenticated user to be exploited.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.