CVE-2026-65642

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 22:16

Updated : 2026-09-03 17:02


NVD link : CVE-2026-65642

Mitre link : CVE-2026-65642

CVE.ORG link : CVE-2026-65642


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key