PT-2026-85033 · Plesk · Plesk

CVE-2026-67397

·

Published

2026-09-03

·

Updated

2026-09-04

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Plesk versions 18.0.79.9 and earlier Plesk versions 18.0.80 through 18.0.80.5
Description A path traversal issue allows local users to execute arbitrary code with root privileges. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference files with input that is not properly neutralized.
Recommendations Update to version 18.0.79.10 or later. Update to version 18.0.80.6 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67397

Affected Products

Plesk