CVE-2026-67394
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
| CWE | CWE-78 |
| Vendor | webpros |
| Product | plesk |
| Published | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for webpros plesk
Be the first to know when new unknown vulnerabilities affecting webpros plesk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WebPros / Plesk
18.0.34 < 18.0.79.9 18.0.80 < 18.0.80.5
References
Credits
Aziz Knani