CVE-2026-67394: OS Command Injection
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Plesk for Linuxto a version that resolves this vulnerability.Fixed in 18.0.79.9 - Upgrade
Upgrade
Plesk for Linuxto a version that resolves this vulnerability.Fixed in 18.0.80.5
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A customer or reseller who has shell access can exploit it. It also affects customers or resellers who are permitted to change their own shell-access settings.
Which installations are affected?
Plesk for Linux versions from 18.0.34 before 18.0.79.9 are affected, as is version 18.0.80 before 18.0.80.5. Systems outside those stated ranges are not identified as affected by the provided information.
What level of access could an attacker gain?
Successful exploitation allows the affected customer or reseller to elevate privileges to the root account on the hosting server.