AI analysis
Plesk Obsidian versions 18.0.34 through 18.0.80.7 and 18.0.81.0 contain an untrusted search path flaw (CWE-426) that is exploitable when the Plesk RESTful API extension (versions 2.4.2 through 2.4.6) is installed. A remote attacker with any valid Plesk account (low-privilege, authenticated access is sufficient) can trigger the flaw through the extension's API, causing Plesk to load and execute a malicious component from an attacker-influenced path. Successful exploitation yields arbitrary code execution as root, giving full compromise of the host and every website and customer account it serves. This affects Plesk-powered hosting servers, VPS instances, and dedicated servers where the RESTful API extension is enabled; exploitation status is currently none known (not in CISA KEV, no public PoC).
What to do: Update Plesk to 18.0.80.8 or 18.0.81.1 (or later) and update the RESTful API extension to 2.4.7 or later. If the RESTful API extension is not required, remove or disable it as the simplest mitigation. Audit Plesk authentication and extension logs for unexpected API activity by low-privileged accounts, and restrict access to the Plesk panel and API to trusted networks or VPNs.
Affected
| Plesk Obsidian | 18.0.34 to before 18.0.80.8; 18.0.81 to before 18.0.81.1 |
| Plesk RESTful API extension | 2.4.2 to before 2.4.7 |
Estimated exposure
largeTens of thousands of exposed servers (subset of ~100k+ Plesk servers running the RESTful API extension) — Public internet scans (Shodan/Censys) typically show tens of thousands of Plesk admin portals exposed on port 8443 and the vendor cites hundreds of thousands of installations, of which only those running RESTful API extension 2.4.2–2.4.6…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.