Local Privilege Escalation Vulnerability in Plesk for Linux
CVE-2026-67394

9CRITICAL

Key Information:

Vendor

Webpros

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-67394?

A local privilege escalation vulnerability in Plesk for Linux enables customers or resellers with shell access to exploit OS command injection. This issue affects all versions from 18.0.34 prior to 18.0.79.9 and version 18.0.80.5, allowing unauthorized escalation of privileges to the root account, posing significant security risks to hosting servers.

Affected Version(s)

Plesk 18.0.34 < 18.0.79.9

Plesk 18.0.80 < 18.0.80.5

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aziz Knani
.