CVE-2026-65646

Summary

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Affected Software

VendorProductVersion RangeStatus
WebProsPlesk0 < 18.0.79.8affected
WebProsPlesk18.0.80 < 18.0.80.4affected

Weaknesses

  • CWE-74: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

References