Junglewise Threat Intelligence

CVE-2026-64639: Plesk privilege escalation via database cloning

CVE-2026-64639 · Severity: info · Published 2026-08-12

Executive brief

Plesk is a hosting control panel used by web hosting providers to manage customer websites and databases. A flaw in its database cloning feature allows low-privileged users (customers or resellers) to escalate their privileges and execute code as the database administrator, potentially gaining full control over hosted databases and customer data.

Technical details

An incorrect implementation of the database cloning process in Plesk allows privilege escalation from low-privileged users (customer, reseller roles) to database server administrator level. The vulnerability exists in versions 18.0.52 through 18.0.79.6 and 18.0.80.2. By exploiting the cloning mechanism, an attacker can execute arbitrary code with database administrator privileges. The vulnerability requires authenticated access (user must have customer or reseller account on the Plesk instance). Patches are available in versions 18.0.79.6 and later.

Affected products

  • Plesk Plesk 18.0.52 before 18.0.79.6 and 18.0.80.2

Timeline

  • 2026-08-12: disclosed

References

Related threats