Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) — High Severity

A significant security flaw has been identified in Plesk Obsidian, a popular web hosting control panel. This vulnerability, tracked as CVE-2025-65518, could allow attackers to disrupt the normal operation of affected Plesk instances, leading to a denial of service (DoS) for legitimate users. Understanding this issue is crucial for administrators and developers to protect their web environments.

CVE Details

  • Product: Plesk Obsidian
  • Published Date: January 8, 2026
  • Severity: High
  • Status: Analyzed

Affected Products

The Denial of Service vulnerability impacts Plesk Obsidian versions 8.0.1 through 18.0.73. If you are running any of these versions, your system could be at risk.

Current Status

The vulnerability has been officially “Analyzed.” This means the issue has been recognized and its characteristics understood. While this confirms the existence and nature of the flaw, it also indicates that users should be actively looking for official communications from Plesk regarding patches or mitigation strategies.

Severity Level

Rated as “High” severity with a CVSS score of 7.5, this Denial of Service (DoS) vulnerability is a serious concern. The flaw lies within the get_password.php endpoint of the Plesk Obsidian web interface. An attacker can craft a specific request containing a malicious payload. When this payload is processed, it causes the web interface to continuously reload, making it inaccessible. Crucially, this attack can be carried out remotely and without any authentication, meaning even unauthorized individuals can potentially exploit it. A successful attack will lead to a persistent disruption of service, impacting the availability of the Plesk Obsidian instance and any websites or services it manages.

Possible Solutions

Given the high severity and the potential for unauthenticated remote exploitation, it is imperative for administrators to take immediate action. As this vulnerability has been analyzed, Plesk is expected to release official patches or updates to address it. We strongly advise all users of affected Plesk Obsidian versions to:

  • Monitor Official Channels: Regularly check the official Plesk website and documentation (specifically their release notes and security advisories) for updates. The link to their release notes is provided below.
  • Apply Patches Promptly: Once official patches or updated versions are released, apply them to your Plesk Obsidian instances without delay.
  • Keep All Software Updated: Beyond this specific CVE, maintain a regular schedule for updating all software, operating systems, and applications on your servers to protect against known vulnerabilities.

References

Hosting Control Panel

https://docs.plesk.com/release-notes/obsidian/change-log/

https://github.com/Jainil-89/CVE-2025-65518/blob/main/cve.md

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.