CVE-2026-67394 PUBLISHED

Assigner: hackerone
Reserved: 29.07.2026 Published: 01.09.2026 Updated: 01.09.2026

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9

Product Status

Vendor WebPros
Product Plesk
Versions Default: unaffected
  • affected from 18.0.34 to 18.0.79.9 (excl.)
  • affected from 18.0.80 to 18.0.80.5 (excl.)

Workarounds

Disable shell access for customers or resellers if it is not required (make sure their service plan does not allow to change it)

Credits

  • Aziz Knani finder

References

Problem Types

  • CWE-78 OS Command Injection CWE