Security Advisory

CVE-2026-64637

9.9
CRITICAL

Vulnerability Description

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
Published Date August 7, 2026
Official Source NIST NVD Advisory