ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

WebPros security advisory (AV26-866)

mediumAdvisoryimportance 30CVE-2026-67394
AI summary · glm-5.3-flash

Canada's Cyber Centre relays a WebPros advisory for CVE-2026-67394, a Plesk privilege escalation flaw to root, fixed in 18.0.79.9 and 18.0.80.5.

The Canadian Centre for Cyber Security issued alert AV26-866 relaying WebPros' security advisory for Plesk. CVE-2026-67394 allows privilege escalation to root and affects Plesk versions prior to 18.0.79.9 and 18.0.80.5. Administrators are encouraged to review the advisory and apply the available updates.

  • CVE-2026-67394 enables privilege escalation to root in Plesk
  • Affected versions are prior to 18.0.79.9 and 18.0.80.5
  • Issued as Canadian Cyber Centre alert AV26-866 on September 1, 2026
  • Users and administrators urged to apply updates

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-67394
Command Injection Local Privilege Escalation in Plesk for Linux

CVE-2026-67394 is an OS command injection flaw (CWE-78) in Plesk for Linux that lets a low-privileged hosting tenant escalate to the root account on the hosting server. It is triggered by a customer or reseller who has shell access — or is allowed to change their own shell access setting — causing injected operating-system commands to run with elevated privileges; the CVSS network attack vector reflects that this can be done remotely by an authenticated tenant account. Successful exploitation yields full root control of the server, with high impact on confidentiality, integrity, and availability, and on the security of all sites hosted on that box. All Plesk for Linux installations running versions from 18.0.34 prior to 18.0.79.9 and prior to 18.0.80.5 are affected. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS gives it a 1.3% chance of exploitation within 30 days, so no active exploitation is currently known.

Do: Upgrade Plesk for Linux to version 18.0.79.9 or 18.0.80.5 (or later) per the WebPros advisory (AV26-866). As an interim mitigation, audit subscriptions and revoke or restrict customer/reseller shell access, including the privilege to change one's own shell access setting. Review hosting server logs for unexpected root-level command execution originating from tenant accounts.

9.01%
  • Plesk (WebPros) Plesk for Linux all versions from 18.0.34 before 18.0.79.9 and before 18.0.80.5
largetens of thousands of hosting servers (Plesk is deployed on roughly 200,000 servers worldwide; the exploitable subset is Linux servers with customer/reseller…
Full article

Serial number: AV26-866 Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root

This source does not provide full text. Read it at cyber.gc.ca.