Executive brief
Plesk is a hosting control panel used by server administrators to manage multiple customer accounts. A flaw in its database management interface allows authenticated users to access and modify databases belonging to other customers on the same server, potentially exposing sensitive customer data and compromising service integrity.
Technical details
An insecure direct object reference (IDOR) vulnerability exists in Plesk's database management interface, allowing authenticated users to read and modify databases of other customers by manipulating object references without proper authorization checks. The vulnerability affects Plesk versions 18.0.79.7 and earlier, and versions 18.0.80 through 18.0.80.3. Exploitation requires valid authentication to the Plesk control panel and network access to the vulnerable interface. An authenticated attacker can access, modify, or delete arbitrary customer databases, leading to data compromise and service disruption. Patches are available in later versions.
Affected products
- Plesk Plesk 18.0.79.7 and earlier, 18.0.80 through 18.0.80.3
Timeline
- 2026-08-26: disclosed