CVE-2026-65642
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
- Published Aug 26, 2026
- CVSS 8.6 high
- 0.5% chance of exploitation in the next 30 days (EPSS)