CVE-2026-68489
largeAuthenticated root code execution in Plesk Ruby & Node.js Toolkit extensions
CVE-2026-68489 is a static code injection flaw (CWE-96) in two Plesk server extensions: Ruby before version 1.6.6 and Node.js Toolkit before version 2.5.0. A remote attacker with any valid (low-privileged) Plesk account can inject arbitrary code through custom environment variables configured for Ruby or Node.js applications; the injected code is executed with root privileges on the hosting server. Successful exploitation gives the attacker full control of the underlying server, affecting all hosted sites and customers on that machine. The bug affects Plesk servers where either extension is installed at a vulnerable version, and is rated high severity (CVSS 4.0: 8.7) because it requires only network access and low privileges, with no user interaction. No public proof of concept is known and the flaw is not listed in CISA's KEV catalog, indicating no confirmed in-the-wild exploitation at this time.
What to do: Update the Ruby extension to 1.6.6 or later and the Node.js Toolkit extension to 2.5.0 or later via the Plesk Extensions catalog. Audit custom environment variables previously set through both extensions for suspicious or unfamiliar entries, and review server logs for unexpected root-level processes or persistence. If the extensions are not needed, remove them; additionally restrict Plesk login exposure (VPN/IP allowlisting) since exploitation requires a valid account.
| Plesk Ruby (Plesk extension) | before 1.6.6 |
| Plesk Node.js Toolkit (Plesk extension) | before 2.5.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
- Weakness
- CWE-96
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.