PT-2025-33731 · Unknown · Plesk Obsidian
Aziz
·
Published
2025-08-19
·
Updated
2025-09-26
·
CVE-2025-54336
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Plesk Obsidian version 18.0.70
Description:
The
isAdminPasswordValid function in Plesk Obsidian uses a weak comparison (==) which allows an attacker to bypass the administrator password if the correct password is in the format "0e" followed by any digit string. An attacker can then log in using any string that evaluates to 0.0, such as "0e0". This issue is located in the admin/plib/LoginManager.php file. Approximately 11.6 million services are estimated to be affected worldwide.Recommendations:
Plesk Obsidian version 18.0.70: Update to a newer version that addresses this authentication bypass issue. As a temporary workaround, consider restricting access to the
admin/plib/LoginManager.php file until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plesk Obsidian