Blind SQL Injection Vulnerability in Plesk Obsidian
Plesk Obsidian versions prior to 18.0.80.1 and 18.0.79.5 are vulnerable to a blind SQL injection (CVE-2026-64636) which allows unauthenticated or low-privileged attackers to execute unauthorized database queries.
WebPros has released a security advisory regarding a critical blind SQL injection vulnerability, tracked as CVE-2026-64636, affecting Plesk Obsidian. This vulnerability exists in versions prior to 18.0.80.1 and 18.0.79.5. The flaw enables an attacker to manipulate backend database queries, potentially leading to unauthorized data exposure, modification, or administrative account compromise. Given the prevalence of Plesk in web hosting environments, this vulnerability presents a significant risk to hosted websites and server management configurations. Security teams should prioritize patching Plesk installations to the latest versions to mitigate the risk of remote database exploitation.
Impact
Successful exploitation of CVE-2026-64636 allows an attacker to interact with the underlying database of the Plesk management interface. This can lead to the exfiltration of sensitive configuration data, user credentials, or the ability to modify web application settings. The scope includes all server environments running outdated versions of Plesk Obsidian that are exposed to the internet.
Recommendation
- Upgrade all Plesk Obsidian instances to version 18.0.80.1, 18.0.79.5, or later immediately.
- Review web server access logs for anomalous requests containing SQL syntax (e.g., SELECT, UNION, SLEEP) targeting the Plesk management interface endpoints.
- Restrict access to the Plesk admin panel by IP address or VPN to minimize the attack surface until patches are applied.
Immediate actions
Patch Plesk Obsidian to 18.0.80.1 or 18.0.79.5 to address CVE-2026-64636
Mitigations
Restrict external network access to the Plesk management interface
CVE-2026-64636