CVE-2026-64639Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-12); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-12: 2Mentions · 2026-08-13: 2Patch / Workaround · 2026-08-13: 2Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 208-1208-13
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-122
Disclosure2
2026-08-132
Patch2
Full discourse4 posts
  • Sami Laiho@samilaiho
    Patch

    Vulnerability in Plesk URL: https://support.plesk.com/hc/en-us/articles/42521305418903-Vulnerability-CVE-2026-64639-Privilege-Escalation-via-Database-Cloning-in-Plesk Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.5

    Post summary

    The article announces a critical privilege‑escalation flaw (CVE‑2026‑64639) in Plesk, cites an official vendor fix, and provides CVSS metrics, but does not disclose PoC or active exploitation evidence.

    02020968
    30.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability CVE-2026-64639 in #Plesk allows a customer who can clone or copy a database on the server to potentially obtain database server administrator privileges. Advisory at: https://support.plesk.com/hc/en-us/articles/42521305418903-Vulnerability-CVE-2026-64639-Privilege-Escalation-via-Database-Cloning-in-Plesk #Patch #Patch #Patch

    Post summary

    A warning about CVE‑2026‑64639 in Plesk, highlighting a privilege escalation flaw via database cloning, with an advisory link and patch suggested.

    01000312
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-64639 Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on… https://www.cve.org/CVERecord?id=CVE-2026-64639 ----- Traducción: CVE-2026-64639 Pro… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-64639, noting that an improper database cloning process in Plesk can enable arbitrary code execution by low‑privileged users, but it provides no PoC, exploit, active exploitation evidence, or mitigation details.

    0000034
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-64639 Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on… https://www.cve.org/CVERecord?id=CVE-2026-64639

    Post summary

    The post announces CVE-2026-64639, detailing an arbitrary code execution vulnerability in Plesk's database cloning process for certain versions, without providing PoC, exploit code, or patch information.

    000001.1K
    57.9K followersView on X

Explore more