kb: security
Situation
A security vulnerability was discovered in Plesk that allows an authentication bypass, resulting in privilege escalation from a Reseller-level account to root.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk | 18.0.80 and earlier | 18.0.80.1 and 18.0.79.5 |
Impact
An attacker with Reseller-level access could gain full root-level control of the server.
Call to action
Update Plesk to the latest build: How to update Plesk Obsidian to the latest build
Mitigation
If you are unable to update immediately, you can reduce risk from this issue by either of the following:
- Disabling OS-level system logins for resellers by setting
systemAdmin = offunder the[login]section of Panel.ini. - Disabling API access for reseller accounts via the relevant service plan permission.
We strongly recommend updating the latest hotfix version as soon as possible.
Please reach out to our support team if you have any questions or need further guidance.
Acknowledgement
We would like to thank Aziz Knani for responsibly disclosing this vulnerability.
Comments
Ik am getting tired of these CVEs lately. Plesk becoming unreliable.
Please sign in to leave a comment.