Articles in this section

Vulnerability CVE-2026-67397: Arbitrary code execution as root in Plesk

kb: security kb: ai-created

A security vulnerability was discovered in Plesk that could allow a Plesk user to execute arbitrary code as root on the server. This security vulnerability has been identified as CVE-2026-67397.

Affected product version

Product Affected versions Patched versions
Plesk for Linux 18.0.79.9 or earlier
18.0.80 - 18.0.80.5
18.0.79.10
18.0.80.6
Plesk for Windows Not affected Not applicable

Impact

Arbitrary code execution as root is possible. A Plesk user without elevated privileges could gain full control of the server.

Call to Action

Update to Plesk Obsidian to 18.0.79.10 or 18.0.80.6 or later: How to update Plesk Obsidian to the latest build

How to confirm the patched version is installed

The version shown should be Plesk Obsidian 18.0.79.10 or 18.0.80.6 or later: How to find version of Plesk installed on server?

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.