CVE-2026-67397
massLocal Path Traversal to Root Code Execution in Plesk 18.0.79/18.0.80
CVE-2026-67397 is a path traversal vulnerability (CWE-22) in Plesk, a widely used web hosting control panel, affecting builds 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5. A local, low-privileged user triggers it by supplying a path that traverses outside an intended directory, which is then processed by privileged Plesk components and allows the attacker's code to run. The attacker gains arbitrary code execution as root on the hosting server, meaning full control of the host, its configuration, and the sites and data it hosts. Any operator running the affected releases is in scope, but the CVSS 4.0 vector (AV:L/PR:L/UI:N, scored 8.5 High) confirms exploitation requires local access such as a hosted customer's shell or FTP account rather than unauthenticated remote access. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns a roughly 0.1% probability of exploitation within 30 days.
What to do: Upgrade Plesk to a release newer than 18.0.80.5 (or newer than 18.0.79.9 on the 18.0.79 line) and verify the running version with 'plesk version' or the panel's About page. Until patched, restrict local shell and FTP logins on affected hosts to trusted users, since exploiting this flaw requires a low-privileged local account.
| Plesk | 18.0.79.9 and earlier |
| Plesk | 18.0.80 through 18.0.80.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.