Critical severity9.9NVD Advisory· Published Aug 7, 2026· Updated Aug 7, 2026
CVE-2026-64637
CVE-2026-64637
Description
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.