ZeroHour
Product

Plesk

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

WebPros security advisory (AV26-866)

Canada's Cyber Centre relays a WebPros advisory for CVE-2026-67394, a Plesk privilege escalation flaw to root, fixed in 18.0.79.9 and 18.0.80.5.

The Canadian Centre for Cyber Security issued alert AV26-866 relaying WebPros' security advisory for Plesk. CVE-2026-67394 allows privilege escalation to root and affects Plesk versions prior to 18.0.79.9 and 18.0.80.5. Administrators are encouraged to review the advisory and apply the available updates.

WebPros security advisory (AV26-854)

Canadian Centre for Cyber Security relayed a WebPros advisory covering Plesk vulnerabilities CVE-2026-65642 and CVE-2026-65647 with fixed versions released.

WebPros released a security advisory affecting Plesk versions prior to 18.0.79.8 and 18.0.80.4, Plesk Migrator prior to 2.36.0, and Plesk Site Import prior to 1.12.1. The listed vulnerabilities are CVE-2026-65642 in Plesk's database management interface and CVE-2026-65647 in the Site Import and Migrator extensions. The Canadian Centre for Cyber Security (AV26-854) encourages users and administrators to apply the available updates.

Related CVEs

  • Command Injection Local Privilege Escalation in Plesk for Linux
    CVE-2026-67394 is an OS command injection flaw (CWE-78) in Plesk for Linux that lets a low-privileged hosting tenant escalate to the root account on the hosting server. It is triggered by a customer or reseller who has shell access — or is allowed to change their own shell access setting — causing injected operating-system commands to run with elevated privileges; the CVSS network attack vector reflects that this can be done remotely by an authenticated tenant account. Successful exploitation yields full root control of the server, with high impact on confidentiality, integrity, and availability, and on the security of all sites hosted on that box. All Plesk for Linux installations running versions from 18.0.34 prior to 18.0.79.9 and prior to 18.0.80.5 are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS gives it a 1.3% chance of exploitation within 30 days, so no active exploitation is currently known.
    · Plesk (WebPros) Plesk for Linux all versions from 18.0.34 before 18.0.79.9 and before 18.0.80.5large
  • Authenticated Root RCE via Improper Symlink Handling in Plesk
    Plesk, the WebPros hosting control panel, resolves symlinks without verifying their targets before file access (CWE-59, link following), so privileged panel operations can be redirected through an attacker-controlled symlink. The flaw is triggered remotely by an authenticated low-privileged user — for example a tenant account on a shared hosting server — who gets Plesk's privileged file operations to follow a malicious link. A successful attacker executes arbitrary code with root privileges on the hosting server, compromising the control panel, every site it hosts, and the underlying OS. All Plesk deployments are potentially affected, but the specific vulnerable version range is not given in the available data, so operators should consult WebPros advisory AV26-854 for fixed releases. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.
    · Plesk (WebPros) Pleskmass
  • Authenticated IDOR in WebPros Plesk exposes other customers' databases
    CVE-2026-65642 is an insecure direct object reference (IDOR, CWE-639) in Plesk, the WebPros hosting control panel, affecting versions 18.0.79.7 and earlier as well as 18.0.80 through 18.0.80.3. A remote user with a valid account on the server can reference a database identifier belonging to a different customer without an ownership check, because the application fails to verify that the requested object belongs to the requesting user. This lets the attacker read and modify other customers' databases on a shared Plesk server, giving high confidentiality and integrity impact but no availability impact (CVSS 4.0: 8.6 High). Exposure is concentrated in multi-tenant hosting environments, where hosting providers and agencies run one Plesk server for many customer accounts; single-tenant deployments have little to lose from this flaw. As of now there is no public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days, so exploitation has not been observed.
    · WebPros Plesk 18.0.79.7 and earlier; 18.0.80 through 18.0.80.3large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.