CVE-2026-64636

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-07 18:17

Updated : 2026-09-03 17:02


NVD link : CVE-2026-64636

Mitre link : CVE-2026-64636

CVE.ORG link : CVE-2026-64636


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')