ZeroHour

CVE-2026-67394

large

Command Injection Local Privilege Escalation in Plesk for Linux

CVSS 4.0
9.0 critical
EPSS
1%p68
Published
()
Modified
AI analysis

CVE-2026-67394 is an OS command injection flaw (CWE-78) in Plesk for Linux that lets a low-privileged hosting tenant escalate to the root account on the hosting server. It is triggered by a customer or reseller who has shell access — or is allowed to change their own shell access setting — causing injected operating-system commands to run with elevated privileges; the CVSS network attack vector reflects that this can be done remotely by an authenticated tenant account. Successful exploitation yields full root control of the server, with high impact on confidentiality, integrity, and availability, and on the security of all sites hosted on that box. All Plesk for Linux installations running versions from 18.0.34 prior to 18.0.79.9 and prior to 18.0.80.5 are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS gives it a 1.3% chance of exploitation within 30 days, so no active exploitation is currently known.

What to do: Upgrade Plesk for Linux to version 18.0.79.9 or 18.0.80.5 (or later) per the WebPros advisory (AV26-866). As an interim mitigation, audit subscriptions and revoke or restrict customer/reseller shell access, including the privilege to change one's own shell access setting. Review hosting server logs for unexpected root-level command execution originating from tenant accounts.

Affected
Plesk (WebPros) Plesk for Linuxall versions from 18.0.34 before 18.0.79.9 and before 18.0.80.5
Estimated exposure
largetens of thousands of hosting servers (Plesk is deployed on roughly 200,000 servers worldwide; the exploitable subset is Linux servers with customer/reseller… — Based on vendor-reported deployment of approximately 200,000 Plesk servers, the majority of which run Linux, reduced to the subset of those servers where tenants have, or can grant themselves, shell access.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

WebPros security advisory (AV26-866)

Canada's Cyber Centre relays a WebPros advisory for CVE-2026-67394, a Plesk privilege escalation flaw to root, fixed in 18.0.79.9 and 18.0.80.5.

The Canadian Centre for Cyber Security issued alert AV26-866 relaying WebPros' security advisory for Plesk. CVE-2026-67394 allows privilege escalation to root and affects Plesk versions prior to 18.0.79.9 and 18.0.80.5. Administrators are encouraged to review the advisory and apply the available updates.