Plesk Incorrect Access Control Vulnerability (CVE-2025-66430) — Critical Severity

A significant security flaw has been discovered in Plesk 18.0, a popular web hosting control panel. This vulnerability, identified as CVE-2025-66430, stems from incorrect access control within the system. The critical issue allows an attacker to exploit Password Protected Directories, leading to unauthorized root-level access on a Plesk server. This means a regular Plesk user could potentially gain complete control over the server, posing a severe risk to data integrity and system security.

CVE Details

This vulnerability is officially documented under the following details:

  • Product: Plesk 18.0
  • Published: December 12, 2025
  • Severity: CRITICAL
  • Status: Analyzed

Affected Products

The core product affected by this severe access control issue is:

  • Plesk 18.0

Users running Plesk version 18.0 should take immediate action to address this vulnerability.

Current Status

The vulnerability status is “Analyzed,” indicating that the issue has been thoroughly investigated and confirmed by security researchers and the vendor. This status typically precedes the release of patches or detailed mitigation advice.

Severity Level

CVE-2025-66430 has been assigned a CRITICAL severity level with a CVSS score of 9.1. This high score reflects the serious nature of the vulnerability. A critical rating means that exploiting this flaw can lead to significant impacts, such as full system compromise, data theft, or denial of service, often with minimal effort from an attacker. The ability for a regular user to gain root access is a particularly dangerous outcome, as it bypasses all standard security measures and allows for complete control over the compromised server.

Possible Solutions

Given the critical nature of this incorrect access control vulnerability, it is imperative for all Plesk 18.0 users to implement available fixes promptly. The most effective solution will be to apply the official security updates or patches released by Plesk. System administrators and developers should:

  1. Check for Official Patches: Regularly monitor the official Plesk support portal and release notes for security advisories related to CVE-2025-66430.
  2. Apply Updates Immediately: Once a patch or updated version is available, apply it to your Plesk 18.0 installation without delay. Keeping your software up-to-date is the most crucial step in protecting against known vulnerabilities.
  3. Follow Plesk’s Security Recommendations: Adhere to all security best practices outlined by Plesk for server hardening and access management.

Always back up your data before performing any system updates or changes to ensure a smooth recovery in case of unexpected issues.

References

https://docs.plesk.com/release-notes/obsidian/whats-new/

https://support.plesk.com/hc/en-us/articles/36261922405015–CVE-2025-66430-Security-vulnerability-in-Password-Protected-Directories-allows-Plesk-users-to-gain-root-level-access-to-a-Plesk-server

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.