WebPros security advisory (AV26-866)
Canada's Cyber Centre relays a WebPros advisory for CVE-2026-67394, a Plesk privilege escalation flaw to root, fixed in 18.0.79.9 and 18.0.80.5.
The Canadian Centre for Cyber Security issued alert AV26-866 relaying WebPros' security advisory for Plesk. CVE-2026-67394 allows privilege escalation to root and affects Plesk versions prior to 18.0.79.9 and 18.0.80.5. Administrators are encouraged to review the advisory and apply the available updates.
- CVE-2026-67394 enables privilege escalation to root in Plesk
- Affected versions are prior to 18.0.79.9 and 18.0.80.5
- Issued as Canadian Cyber Centre alert AV26-866 on September 1, 2026
- Users and administrators urged to apply updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-67394 | Command Injection Local Privilege Escalation in Plesk for Linux CVE-2026-67394 is an OS command injection flaw (CWE-78) in Plesk for Linux that lets a low-privileged hosting tenant escalate to the root account on the hosting server. It is triggered by a customer or reseller who has shell access — or is allowed to change their own shell access setting — causing injected operating-system commands to run with elevated privileges; the CVSS network attack vector reflects that this can be done remotely by an authenticated tenant account. Successful exploitation yields full root control of the server, with high impact on confidentiality, integrity, and availability, and on the security of all sites hosted on that box. All Plesk for Linux installations running versions from 18.0.34 prior to 18.0.79.9 and prior to 18.0.80.5 are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS gives it a 1.3% chance of exploitation within 30 days, so no active exploitation is currently known. Do: Upgrade Plesk for Linux to version 18.0.79.9 or 18.0.80.5 (or later) per the WebPros advisory (AV26-866). As an interim mitigation, audit subscriptions and revoke or restrict customer/reseller shell access, including the privilege to change one's own shell access setting. Review hosting server logs for unexpected root-level command execution originating from tenant accounts. | 9.0 | 1% |
| largetens of thousands of hosting servers (Plesk is deployed on roughly 200,000 servers worldwide; the exploitable subset is Linux servers with customer/reseller… |
Serial number: AV26-866 Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root
This source does not provide full text. Read it at cyber.gc.ca.