CVE-2026-65642: WebPros Plesk

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

Affected products

  • WebPros Plesk: up to and including 18.0.79.7; from 18.0.80, before 18.0.80.4 (fixed in 18.0.80.4)

Published 2026-08-26. Last modified 2026-09-03.