Summary
- CVE-2026-65642 can give an authenticated Plesk customer unauthorised read and write access to other users' databases on the same server.
- CVE-2026-65646 can expose arbitrary server files and potentially disclose Plesk administrator and database credentials.
- Plesk has fixed both vulnerabilities in versions 18.0.79.8 and 18.0.80.4.
Plesk has fixed two vulnerabilities that can break isolation between customers on shared hosting servers, including one issue capable of exposing administrative credentials and giving an attacker control of the Plesk management panel.
CVE-2026-65642 affects Plesk’s database management interface. An authenticated customer can gain unauthorised access to databases belonging to other users on the same server, including the ability to read, modify, or delete their information.
The second issue, CVE-2026-65646, affects DNS zone management on Plesk for Linux. A customer with an ordinary hosting subscription and a DNS-managed domain may be able to read arbitrary files that should not be accessible to the account.
Plesk says those files can include administrator and database credentials. If disclosed, the credentials could give an attacker full control of the Plesk panel and access to all databases hosted on the affected server.
Both vulnerabilities are fixed in Plesk 18.0.79.8 and 18.0.80.4. CVE-2026-65642 affects both Linux and Windows versions, while CVE-2026-65646 applies to Linux servers where customers are permitted to manage DNS records for their own domains.
No exploitation has been reported by Plesk in the advisories. The security consequence comes from the trust boundary involved rather than evidence of an active campaign.
Shared hosting depends on several customers using the same underlying server while remaining isolated from one another. Application files, databases, credentials, and administrative privileges belonging to one tenant should not become reachable from an account assigned to another.
CVE-2026-65642 undermines that model directly by allowing one authenticated customer to reach another’s database. CVE-2026-65646 can go further if exposed server files disclose the credentials needed to control the administrative layer itself.
The combination illustrates the privileged role occupied by hosting control panels. Products such as Plesk bring website management, databases, domains, DNS, credentials, extensions, and server administration into a common interface. That simplifies hosting operations, but it also creates a management plane through which a security flaw can cross otherwise separate workloads.
The exposure is not limited to organisations operating their own servers. Businesses buying managed or shared hosting can have securely written applications and still inherit weaknesses in the provider’s underlying control plane.
That creates an asymmetry during incident response. Hosting providers can inspect platform-level logs, patch state, server access, and cross-tenant behaviour, while individual customers generally see only their own subscription and application environment.
If a vulnerability allows movement across tenant boundaries, establishing who was affected may therefore depend on evidence held by the provider rather than the customer whose information was reached.
The same issue affects credential response. Applying a software update prevents continued exploitation of the underlying flaw, but credentials exposed before remediation may remain valid. Where server or administrative secrets could have been read, determining whether they require rotation becomes a separate part of restoring confidence in the environment.
Plesk’s fixed releases close the documented vulnerabilities, and the company tells administrators to verify that patched versions are installed. The absence of reported exploitation reduces the immediate incident pressure, but the potential impact reaches considerably beyond a single website because both flaws operate against shared management functions.
For hosting infrastructure, isolation is one of the product’s fundamental security guarantees. Vulnerabilities that allow ordinary customers to cross that boundary therefore deserve attention even before evidence of widespread exploitation emerges.





