CVE-2026-87898: OS Command Injection
Published Sep 23, 2026
·Updated
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
Affected Software
1 affected component
Plesk Plesk
Event History
Sep 23, 2026
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The attacker must be authenticated to Plesk and able to reach the affected service remotely.
2
What is the potential impact after successful exploitation?
Successful exploitation can allow execution of arbitrary code with root privileges.