CVE-2026-64637
CRITICAL
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Aug 07, 2026
Vendor
unknown
Description
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.