CVE-2026-65642

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.


We have discovered 102,151 live websites that are affected by CVE-2026-65642.

Run a Free Instant Scan




Affected Software

Product  Plesk
Category Hosting Panels
Vulnerable Domains102,151 live websites (100% of Plesk install base)
Vulnerable Versions
  • from 0 through 18.0.79.7
  • from 18.0.80 through 18.0.80.4
Vulnerable Versions Count61 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • Aziz Knani (reporter)

Website Distribution by Country

Number of websites using CVE-2026-65642
United States15,653 websites



Germany28,038 websites
Netherlands10,697 websites
Spain6,175 websites
Turkey5,640 websites
France5,327 websites
GB5,239 websites
Italy4,867 websites
India1,585 websites
Lithuania1,226 websites

Website Distribution by TLD

Number of websites using CVE-2026-65642
.com33,951 websites
.de16,174 websites
.nl8,775 websites
.it4,111 websites
.net3,498 websites
.org3,269 websites
.co.uk2,891 websites
.es2,601 websites
.fr1,720 websites
.eu1,361 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65642

Top websites that are affected by CVE-2026-65642. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.***.cn United States*,***
*******.com Germany**,***
********.**.uk GB**,***
******.******.com United States**,***
****.********.ru Germany**,***
***********.******.de Germany**,***
********.com United States**,***
**.*******.com Germany**,***
****.***.cn United States**,***
**************.de United States**,***
See full domain list

FAQ

CVE-2026-65642 is Authorization Bypass Through User-Controlled Key in Plesk
A total of 102,151 websites have been identified as vulnerable to CVE-2026-65642, based on global website indexing conducted by WebTechSurvey.
The Plesk is affected by the CVE-2026-65642 vulnerability.
Plesk versions up to 18.0.80.4 are vulnerable to CVE-2026-65642.
CVE-2026-65642 is resolved in version 18.0.80.4 of Plesk.