AI analysis
CVE-2026-67394 is an OS command injection flaw (CWE-78) in Plesk for Linux that lets a low-privileged hosting tenant escalate to the root account on the hosting server. It is triggered by a customer or reseller who has shell access — or is allowed to change their own shell access setting — causing injected operating-system commands to run with elevated privileges; the CVSS network attack vector reflects that this can be done remotely by an authenticated tenant account. Successful exploitation yields full root control of the server, with high impact on confidentiality, integrity, and availability, and on the security of all sites hosted on that box. All Plesk for Linux installations running versions from 18.0.34 prior to 18.0.79.9 and prior to 18.0.80.5 are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS gives it a 1.3% chance of exploitation within 30 days, so no active exploitation is currently known.
What to do: Upgrade Plesk for Linux to version 18.0.79.9 or 18.0.80.5 (or later) per the WebPros advisory (AV26-866). As an interim mitigation, audit subscriptions and revoke or restrict customer/reseller shell access, including the privilege to change one's own shell access setting. Review hosting server logs for unexpected root-level command execution originating from tenant accounts.
Affected
| Plesk (WebPros) Plesk for Linux | all versions from 18.0.34 before 18.0.79.9 and before 18.0.80.5 |
Estimated exposure
largetens of thousands of hosting servers (Plesk is deployed on roughly 200,000 servers worldwide; the exploitable subset is Linux servers with customer/reseller… — Based on vendor-reported deployment of approximately 200,000 Plesk servers, the majority of which run Linux, reduced to the subset of those servers where tenants have, or can grant themselves, shell access.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.