{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/plesk-obsidian/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-64636"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Plesk Obsidian"],"_cs_severities":["high"],"_cs_tags":["vulnerability","sql-injection","web-application"],"_cs_type":"advisory","_cs_vendors":["WebPros"],"content_html":"\u003cp\u003eWebPros has released a security advisory regarding a critical blind SQL injection vulnerability, tracked as CVE-2026-64636, affecting Plesk Obsidian. This vulnerability exists in versions prior to 18.0.80.1 and 18.0.79.5. The flaw enables an attacker to manipulate backend database queries, potentially leading to unauthorized data exposure, modification, or administrative account compromise. Given the prevalence of Plesk in web hosting environments, this vulnerability presents a significant risk to hosted websites and server management configurations. Security teams should prioritize patching Plesk installations to the latest versions to mitigate the risk of remote database exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-64636 allows an attacker to interact with the underlying database of the Plesk management interface. This can lead to the exfiltration of sensitive configuration data, user credentials, or the ability to modify web application settings. The scope includes all server environments running outdated versions of Plesk Obsidian that are exposed to the internet.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Plesk Obsidian instances to version 18.0.80.1, 18.0.79.5, or later immediately.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous requests containing SQL syntax (e.g., SELECT, UNION, SLEEP) targeting the Plesk management interface endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Plesk admin panel by IP address or VPN to minimize the attack surface until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T19:30:39Z","date_published":"2026-08-10T19:30:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-plesk-sql-injection/","summary":"Plesk Obsidian versions prior to 18.0.80.1 and 18.0.79.5 are vulnerable to a blind SQL injection (CVE-2026-64636) which allows unauthenticated or low-privileged attackers to execute unauthorized database queries.","title":"Blind SQL Injection Vulnerability in Plesk Obsidian","url":"https://feed.craftedsignal.io/briefs/2026-08-plesk-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Plesk Obsidian","version":"https://jsonfeed.org/version/1.1"}