PT-2026-83114 · Plesk · Plesk For Linux
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Plesk for Linux versions 18.0.34 through 18.0.79.8
Description
A local privilege escalation issue exists due to OS command injection. This allows a customer or reseller with shell access, or the ability to modify their own shell access, to elevate their privileges to the root account on the hosting server.
Recommendations
Update to version 18.0.79.9 or 18.0.80.5.
Fix
LPE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plesk For Linux