Articles in this section

CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root

kb: security kb: ai-created

Situation

A security vulnerability CVE-2026-67394 was discovered in Plesk that could allow a customer or reseller to escalate privileges to root on the server.

Affected product version

Product Affected versions Patched versions
Plesk for Linux 18.0.34 - 18.0.79.8
18.0.80 - 18.0.80.4
18.0.79.9
18.0.80.5
Plesk for Windows Not affected Not applicable

Impact

Local privilege escalation (LPE) is possible. A customer or reseller account with shell access or allowed to change own shell access could gain root-level control of the server.

Call to Action

Update to Plesk Obsidian 18.0.79.9, 18.0.80.5 or later: How to update Plesk Obsidian to the latest build

How to confirm the patched version is installed

The version shown should be Plesk Obsidian 18.0.79.9, 18.0.80.5 or later: How to find version of Plesk installed on server?

Mitigation

No mitigation is possible if shell access is required. Update to resolve such cases. If shell access is not required by the customers or resellers, it can be disabled to block exploits.

How to disable shell access

Apply this mitigation only if you can't update right now.

  1. Identify subscriptions and domains where shell access is not required by the customer or reseller.
  2. For each one, go to Domains > example.com > Hosting Settings, or the corresponding customer/reseller webspace settings.
  3. Set Shell access to the server to Forbidden.
  4. Make sure the service plan applied to a customer or reseller does not allow changing shell access settings.

Acknowledgements

We would like to thank Aziz Knani for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

1 comment
Date Votes
  • It seems that Plesk is riddled with CVE's and bugs. It's becoming a major, almost daily/weekly, task to update Plesk, or it's extensions or take appropiate measures. Sigh.

    It's like we do not have anything else to do nowadays. We are already very busy as it is. We do not have the time to update everything, every day/week (multiple times). This is becoming insane. 

    1

Please sign in to leave a comment.