External risk intelligence

Plesk Database Cloning Vulnerability Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-64639

Plesk is a widely used web hosting control panel designed to be accessed over the internet by customers and resellers to manage web services, databases, and server configurations, making its management interface a commonly internet-facing service.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a critical vulnerability in Plesk's database cloning process that could allow unauthorized users to execute code with administrative privileges. Understanding the potential impact on our hosted services and customer data is essential.

  • A security flaw allows code execution on Plesk servers.
  • High-risk vulnerability impacts common web hosting platforms.
  • Verify relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low-level access to Plesk, such as a customer or reseller, could exploit an insecure database cloning process. By triggering this vulnerability, the attacker could execute arbitrary code with the privileges of the database server administrator, leading to a critical compromise.

  • Requires low-privileged user access.
  • Triggered by an incorrect database cloning process.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged user could execute arbitrary code on the database server when using the database cloning process in Plesk, potentially impacting the integrity and availability of the database.

  • Database server code execution.
  • Exploits insecure cloning process.
  • Compromised database integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Plesk platform's database cloning process is susceptible to a critical vulnerability, allowing low-privileged users to execute arbitrary code as the database administrator. This impacts the integrity and confidentiality of the database server. Technical leaders and security teams must first confirm the presence and reachability of affected Plesk instances, identify the accountable owner, and assess business criticality to prioritize remediation efforts.

  • Assign ownership to the platform or infrastructure team.
  • Verify Plesk instances and their exposure.
  • Plan remediation during a maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plesk and why is it used?

Plesk is a popular web hosting control panel that provides a graphical interface for managing websites, databases, email accounts, and server settings. It is widely used by hosting providers, web developers, and site owners to simplify server administration and automate routine tasks, such as creating new databases or configuring site environments.

What does CWE-266 mean for CVE-2026-64639?

CWE-266 refers to 'Incorrect Privilege Assignment.' In the context of this vulnerability, it means that the database cloning process in Plesk fails to properly enforce access restrictions. Because of this flaw, a low-privileged user can gain the capabilities of a database administrator, effectively allowing them to perform actions far beyond their authorized permissions.

How is the CVE-2026-64639 vulnerability triggered?

The flaw is triggered when a user with low-level permissions, such as a customer or reseller, initiates the database cloning process. This process does not correctly validate the user's rights, allowing them to force the system to execute code with administrative privileges. Simply logging in or performing standard management tasks that do not involve database cloning does not trigger this vulnerability.

Do I need to worry about this if my Plesk server is internal?

Halo Surface Signal indicates that Plesk is typically designed to be an internet-facing service for customers and resellers to manage web environments. While public-facing instances face the highest risk, internal instances are still vulnerable if an attacker gains initial low-level access to the panel. You should prioritize assessment based on who has access to your Plesk login credentials.

What should I do first to address this vulnerability?

Your first step is to identify all running Plesk instances within your environment and determine if they fall within the affected version range (18.0.52 through 18.0.79.6 or 18.0.80.2). Once identified, coordinate with your infrastructure team to plan an update to a secure version. Review official vendor support resources to confirm the exact patch requirements for your specific installation.

References