Path Traversal Vulnerability in Plesk by Plesk
CVE-2026-67397

8.5HIGH

Key Information:

Vendor

Webpros

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-67397?

A path traversal vulnerability exists in Plesk versions 18.0.79.9 and earlier, as well as versions 18.0.80 through 18.0.80.5. This flaw allows local users to execute arbitrary code with root privileges, potentially compromising the system's integrity. Proper access controls and security practices are essential to mitigate the risks posed by this vulnerability.

Affected Version(s)

Plesk 0 < 18.0.79.9

Plesk 18.0.80 < 18.0.80.5

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.