PT-2026-85033 · Plesk · Plesk
CVE-2026-67397
·
Published
2026-09-03
·
Updated
2026-09-04
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Plesk versions 18.0.79.9 and earlier
Plesk versions 18.0.80 through 18.0.80.5
Description
A path traversal issue allows local users to execute arbitrary code with root privileges. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference files with input that is not properly neutralized.
Recommendations
Update to version 18.0.79.10 or later.
Update to version 18.0.80.6 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plesk