CVE-2026-64636
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
07/08/2026
Last modified:
07/08/2026
Description
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH


