ZeroHour

CVE-2026-67397

mass

Local Path Traversal to Root Code Execution in Plesk 18.0.79/18.0.80

CVSS 4.0
8.5 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-67397 is a path traversal vulnerability (CWE-22) in Plesk, a widely used web hosting control panel, affecting builds 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5. A local, low-privileged user triggers it by supplying a path that traverses outside an intended directory, which is then processed by privileged Plesk components and allows the attacker's code to run. The attacker gains arbitrary code execution as root on the hosting server, meaning full control of the host, its configuration, and the sites and data it hosts. Any operator running the affected releases is in scope, but the CVSS 4.0 vector (AV:L/PR:L/UI:N, scored 8.5 High) confirms exploitation requires local access such as a hosted customer's shell or FTP account rather than unauthenticated remote access. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns a roughly 0.1% probability of exploitation within 30 days.

What to do: Upgrade Plesk to a release newer than 18.0.80.5 (or newer than 18.0.79.9 on the 18.0.79 line) and verify the running version with 'plesk version' or the panel's About page. Until patched, restrict local shell and FTP logins on affected hosts to trusted users, since exploiting this flaw requires a low-privileged local account.

Affected
Plesk18.0.79.9 and earlier
Plesk18.0.80 through 18.0.80.5
Estimated exposure
mass≈200,000+ hosting servers (vendor publicly claims 200k+ Plesk servers) — Plesk is one of the dominant shared-hosting control panels with a vendor-claimed installed base of over 200,000 servers, and the affected ranges cover the current 18.0.79/18.0.80 branches, so most active installs plausibly fall in scope.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

Weakness
CWE-22
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.