Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-64637: Plesk XML-RPC API Allows Unauthorized Root Access
CVE-2026-64637 · published 28 days ago
Summary
Plesk's XML-RPC API has a security issue that lets an authenticated reseller access the root user account without permission. This is a serious issue because it allows someone who shouldn't have access to the root account to gain control over it. To stay secure, update to the latest version of Plesk or apply the necessary patches.
What to do
- Update webpros plesk to version 18.0.80.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | plesk | < 18.0.80.1 |
Original advisory text
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
Severity
9.9
Critical
CVSS 3.0: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published7 Aug 2026
Updated29 Aug 2026
First seen7 Aug 2026
Monitor software like this
Free during beta