A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros plesk |
|
| Vendors & Products |
Webpros
Webpros plesk |
Tue, 01 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via OS Command Injection in Plesk for Linux |
Tue, 01 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-09-01T02:07:41.777Z
Updated: 2026-09-01T13:14:45.804Z
Reserved: 2026-07-29T15:00:02.293Z
Link: CVE-2026-67394
Updated: 2026-09-01T13:14:41.669Z
Status : Received
Published: 2026-09-01T03:16:50.937
Modified: 2026-09-01T14:17:38.217
Link: CVE-2026-67394
No data.