{"id":3229,"date":"2026-01-30T01:31:31","date_gmt":"2026-01-30T01:31:31","guid":{"rendered":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/"},"modified":"2026-01-30T01:31:31","modified_gmt":"2026-01-30T01:31:31","slug":"plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity","status":"publish","type":"post","link":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/","title":{"rendered":"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity"},"content":{"rendered":"<p>A significant security flaw has been identified in Plesk Obsidian, a popular web hosting control panel. This vulnerability, tracked as CVE-2025-65518, could allow attackers to disrupt the normal operation of affected Plesk instances, leading to a denial of service (DoS) for legitimate users. Understanding this issue is crucial for administrators and developers to protect their web environments.<\/p>\n<h2>CVE Details<\/h2>\n<ul>\n<li><strong>Product:<\/strong> Plesk Obsidian<\/li>\n<li><strong>Published Date:<\/strong> January 8, 2026<\/li>\n<li><strong>Severity:<\/strong> High<\/li>\n<li><strong>Status:<\/strong> Analyzed<\/li>\n<\/ul>\n<h2>Affected Products<\/h2>\n<p>The Denial of Service vulnerability impacts Plesk Obsidian versions <strong>8.0.1 through 18.0.73<\/strong>. If you are running any of these versions, your system could be at risk.<\/p>\n<h2>Current Status<\/h2>\n<p>The vulnerability has been officially &#8220;Analyzed.&#8221; This means the issue has been recognized and its characteristics understood. While this confirms the existence and nature of the flaw, it also indicates that users should be actively looking for official communications from Plesk regarding patches or mitigation strategies.<\/p>\n<h2>Severity Level<\/h2>\n<p>Rated as &#8220;High&#8221; severity with a CVSS score of 7.5, this Denial of Service (DoS) vulnerability is a serious concern. The flaw lies within the <code>get_password.php<\/code> endpoint of the Plesk Obsidian web interface. An attacker can craft a specific request containing a malicious payload. When this payload is processed, it causes the web interface to continuously reload, making it inaccessible. Crucially, this attack can be carried out remotely and without any authentication, meaning even unauthorized individuals can potentially exploit it. A successful attack will lead to a persistent disruption of service, impacting the availability of the Plesk Obsidian instance and any websites or services it manages.<\/p>\n<h2>Possible Solutions<\/h2>\n<p>Given the high severity and the potential for unauthenticated remote exploitation, it is imperative for administrators to take immediate action. As this vulnerability has been analyzed, Plesk is expected to release official patches or updates to address it. We strongly advise all users of affected Plesk Obsidian versions to:<\/p>\n<ul>\n<li><strong>Monitor Official Channels:<\/strong> Regularly check the official Plesk website and documentation (specifically their release notes and security advisories) for updates. The link to their release notes is provided below.<\/li>\n<li><strong>Apply Patches Promptly:<\/strong> Once official patches or updated versions are released, apply them to your Plesk Obsidian instances without delay.<\/li>\n<li><strong>Keep All Software Updated:<\/strong> Beyond this specific CVE, maintain a regular schedule for updating all software, operating systems, and applications on your servers to protect against known vulnerabilities.<\/li>\n<\/ul>\n<h2>References<\/h2>\n<blockquote class=\"wp-embedded-content\" data-secret=\"RAa0aKkZlU\"><p><a href=\"https:\/\/www.plesk.com\/\">Hosting Control Panel<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"&#8220;Hosting Control Panel&#8221; &#8212; Plesk\" src=\"https:\/\/www.plesk.com\/embed\/#?secret=AVONFdXdPd#?secret=RAa0aKkZlU\" data-secret=\"RAa0aKkZlU\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>https:\/\/docs.plesk.com\/release-notes\/obsidian\/change-log\/<\/p>\n<p>https:\/\/github.com\/Jainil-89\/CVE-2025-65518\/blob\/main\/cve.md<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A significant security flaw has been identified in Plesk Obsidian, a popular web hosting control panel. This vulnerability, tracked as CVE-2025-65518, could allow attackers to disrupt the normal operation of affected Plesk instances, leading to a denial of service (DoS) for legitimate users. Understanding this issue is crucial for administrators and developers to protect their [&hellip;]<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[785,917,978,779,918],"class_list":["post-3229","post","type-post","status-publish","format-standard","hentry","category-security","tag-denial-of-service","tag-plesk","tag-plesk-obsidian","tag-server-security","tag-web-hosting"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity - Web Hosting and IT Consultancy Services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity - Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"og:description\" content=\"A significant security flaw has been identified in Plesk Obsidian, a popular web hosting control panel. This vulnerability, tracked as CVE-2025-65518, could allow attackers to disrupt the normal operation of affected Plesk instances, leading to a denial of service (DoS) for legitimate users. Understanding this issue is crucial for administrators and developers to protect their [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/\" \/>\n<meta property=\"og:site_name\" content=\"Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-30T01:31:31+00:00\" \/>\n<meta name=\"author\" content=\"Alex Joseph\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Joseph\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/\"},\"author\":{\"name\":\"Alex Joseph\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\"},\"headline\":\"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity\",\"datePublished\":\"2026-01-30T01:31:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/\"},\"wordCount\":409,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"keywords\":[\"Denial of Service\",\"Plesk\",\"Plesk Obsidian\",\"Server Security\",\"Web Hosting\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/\",\"name\":\"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity - Web Hosting and IT Consultancy Services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\"},\"datePublished\":\"2026-01-30T01:31:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"name\":\"Web Hosting and IT Consultancy Services\",\"description\":\"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\",\"name\":\"Web Hosting and IT Consultancy Services\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"contentUrl\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"width\":165,\"height\":50,\"caption\":\"Web Hosting and IT Consultancy Services\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\",\"name\":\"Alex Joseph\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"caption\":\"Alex Joseph\"},\"description\":\"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/author\\\/alexjoseph\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity - Web Hosting and IT Consultancy Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/","og_locale":"en_US","og_type":"article","og_title":"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity - Web Hosting and IT Consultancy Services","og_description":"A significant security flaw has been identified in Plesk Obsidian, a popular web hosting control panel. This vulnerability, tracked as CVE-2025-65518, could allow attackers to disrupt the normal operation of affected Plesk instances, leading to a denial of service (DoS) for legitimate users. Understanding this issue is crucial for administrators and developers to protect their [&hellip;]","og_url":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/","og_site_name":"Web Hosting and IT Consultancy Services","article_published_time":"2026-01-30T01:31:31+00:00","author":"Alex Joseph","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alex Joseph","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/#article","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/"},"author":{"name":"Alex Joseph","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56"},"headline":"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity","datePublished":"2026-01-30T01:31:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/"},"wordCount":409,"commentCount":0,"publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"keywords":["Denial of Service","Plesk","Plesk Obsidian","Server Security","Web Hosting"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/","url":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/","name":"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity - Web Hosting and IT Consultancy Services","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/#website"},"datePublished":"2026-01-30T01:31:31+00:00","breadcrumb":{"@id":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ucartz.com\/updates\/plesk-obsidian-denial-of-service-vulnerability-cve-2025-65518-high-severity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ucartz.com\/updates\/"},{"@type":"ListItem","position":2,"name":"Plesk Obsidian Denial of Service Vulnerability (CVE-2025-65518) \u2014 High Severity"}]},{"@type":"WebSite","@id":"https:\/\/www.ucartz.com\/updates\/#website","url":"https:\/\/www.ucartz.com\/updates\/","name":"Web Hosting and IT Consultancy Services","description":"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!","publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ucartz.com\/updates\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.ucartz.com\/updates\/#organization","name":"Web Hosting and IT Consultancy Services","url":"https:\/\/www.ucartz.com\/updates\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/","url":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","contentUrl":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","width":165,"height":50,"caption":"Web Hosting and IT Consultancy Services"},"image":{"@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56","name":"Alex Joseph","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","caption":"Alex Joseph"},"description":"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.","url":"https:\/\/www.ucartz.com\/updates\/author\/alexjoseph\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/comments?post=3229"}],"version-history":[{"count":0,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3229\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/media?parent=3229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/categories?post=3229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/tags?post=3229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}