CVE-2025-49618: Plesk Obsidian
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
Affected products
- Plesk Obsidian: version 18.0.69 only
Published 2025-07-03. Last modified 2026-06-17.