CVE-2026-67397: Path Traversal
Published Sep 3, 2026
·Updated
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
Affected Software
1 affected component
Plesk Plesk>=18.0.80<=18.0.80.5, <=18.0.79.9
Event History
Sep 3, 2026
CVE Published
via MITRE·11:57 PM
Data Sourced
via MITRE·11:57 PM
DescriptionWeakness
Sep 4, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is exploitable by local users. It is not described as requiring remote access or unauthenticated access.
2
What is the impact of successful exploitation?
A successful attacker can execute arbitrary code with root privileges.
3
Which Plesk versions are affected?
Affected versions are Plesk 18.0.79.9 and earlier, plus Plesk versions from 18.0.80 through 18.0.80.5.