Situation
A security vulnerability CVE-2026-67394 was discovered in Plesk that could allow a customer or reseller to escalate privileges to root on the server.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk for Linux | 18.0.34 - 18.0.79.8 18.0.80 - 18.0.80.4 |
18.0.79.9 18.0.80.5 |
| Plesk for Windows | Not affected | Not applicable |
Impact
Local privilege escalation (LPE) is possible. A customer or reseller account with shell access or allowed to change own shell access could gain root-level control of the server.
Call to Action
Update to Plesk Obsidian 18.0.79.9, 18.0.80.5 or later: How to update Plesk Obsidian to the latest build
How to confirm the patched version is installed
The version shown should be Plesk Obsidian 18.0.79.9, 18.0.80.5 or later: How to find version of Plesk installed on server?
Mitigation
No mitigation is possible if shell access is required. Update to resolve such cases. If shell access is not required by the customers or resellers, it can be disabled to block exploits.
Apply this mitigation only if you can't update right now.
- Identify subscriptions and domains where shell access is not required by the customer or reseller.
- For each one, go to Domains > example.com > Hosting Settings, or the corresponding customer/reseller webspace settings.
- Set Shell access to the server to Forbidden.
- Make sure the service plan applied to a customer or reseller does not allow changing shell access settings.
Acknowledgements
We would like to thank Aziz Knani for responsibly disclosing this vulnerability.
Comments
It seems that Plesk is riddled with CVE's and bugs. It's becoming a major, almost daily/weekly, task to update Plesk, or it's extensions or take appropiate measures. Sigh.
It's like we do not have anything else to do nowadays. We are already very busy as it is. We do not have the time to update everything, every day/week (multiple times). This is becoming insane.
Please sign in to leave a comment.