ZeroHour
Organization

WebPros

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

WebPros security advisory (AV26-866)

Canada's Cyber Centre relays a WebPros advisory for CVE-2026-67394, a Plesk privilege escalation flaw to root, fixed in 18.0.79.9 and 18.0.80.5.

The Canadian Centre for Cyber Security issued alert AV26-866 relaying WebPros' security advisory for Plesk. CVE-2026-67394 allows privilege escalation to root and affects Plesk versions prior to 18.0.79.9 and 18.0.80.5. Administrators are encouraged to review the advisory and apply the available updates.

Related CVEs

  • Command Injection Local Privilege Escalation in Plesk for Linux
    CVE-2026-67394 is an OS command injection flaw (CWE-78) in Plesk for Linux that lets a low-privileged hosting tenant escalate to the root account on the hosting server. It is triggered by a customer or reseller who has shell access — or is allowed to change their own shell access setting — causing injected operating-system commands to run with elevated privileges; the CVSS network attack vector reflects that this can be done remotely by an authenticated tenant account. Successful exploitation yields full root control of the server, with high impact on confidentiality, integrity, and availability, and on the security of all sites hosted on that box. All Plesk for Linux installations running versions from 18.0.34 prior to 18.0.79.9 and prior to 18.0.80.5 are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS gives it a 1.3% chance of exploitation within 30 days, so no active exploitation is currently known.
    · Plesk (WebPros) Plesk for Linux all versions from 18.0.34 before 18.0.79.9 and before 18.0.80.5large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.