CVE-2025-66430

Plesk 18.0 has Incorrect Access Control.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:plesk:plesk:*:*:*:*:*:*:*:*
cpe:2.3:a:plesk:plesk:*:-:*:*:*:*:*:*

History

06 Jan 2026, 14:59

Type Values Removed Values Added
CPE cpe:2.3:a:plesk:plesk:*:-:*:*:*:*:*:*
cpe:2.3:a:plesk:plesk:*:*:*:*:*:*:*:*
First Time Plesk
Plesk plesk
References () https://docs.plesk.com/release-notes/obsidian/whats-new/ - () https://docs.plesk.com/release-notes/obsidian/whats-new/ - Product
References () https://support.plesk.com/hc/en-us/articles/36261922405015--CVE-2025-66430-Security-vulnerability-in-Password-Protected-Directories-allows-Plesk-users-to-gain-root-level-access-to-a-Plesk-server - () https://support.plesk.com/hc/en-us/articles/36261922405015--CVE-2025-66430-Security-vulnerability-in-Password-Protected-Directories-allows-Plesk-users-to-gain-root-level-access-to-a-Plesk-server - Vendor Advisory

12 Dec 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-284

12 Dec 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-12 16:15

Updated : 2026-01-06 14:59


NVD link : CVE-2025-66430

Mitre link : CVE-2025-66430

CVE.ORG link : CVE-2025-66430


JSON object : View

Products Affected

plesk

  • plesk
CWE
CWE-284

Improper Access Control