PT-2026-83114 · Plesk · Plesk For Linux

·

CVE-2026-67394

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Plesk for Linux versions 18.0.34 through 18.0.79.8
Description A local privilege escalation issue exists due to OS command injection. This allows a customer or reseller with shell access, or the ability to modify their own shell access, to elevate their privileges to the root account on the hosting server.
Recommendations Update to version 18.0.79.9 or 18.0.80.5.

Fix

LPE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67394

Affected Products

Plesk For Linux