What is CVE-2026-64637?
CVE-2026-64637 is an improper privilege management issue in the XML-RPC API of Plesk before 18.0.80. It allows an authenticated reseller to obtain an administrative session for the root user account. Immediate update to version 18.0.80+ is required, along with reviewing authentication mechanisms for the XML-RPC API.
Azərbaycanca: CVE-2026-64637, Plesk-in 18.0.80 əvvəl versiyalarında XML-RPC API-də düzgün olmayan imtiyaz idarəetməsidir. Autentifikasiya olunmuş resellerə root istifadəçi hesabı üçün inzibati sessiya əldə etməyə imkan verir. Dərhal 18.0.80+ versiyasına yenilənməli və XML-RPC API üçün autentifikasiya mexanizmləri yoxlanmalıdır.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
In which Plesk component does the CVE-2026-64637 vulnerability exist?
This vulnerability is an improper privilege management issue in the XML-RPC API of Plesk before version 18.0.80.
How can an authenticated reseller exploit CVE-2026-64637?
An authenticated reseller can obtain an administrative session for the root user account through this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.