kb: security
kb: ai-created
A security vulnerability was discovered in Plesk that could allow a Plesk user to execute arbitrary code as root on the server. This security vulnerability has been identified as CVE-2026-67397.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk for Linux | 18.0.79.9 or earlier 18.0.80 - 18.0.80.5 |
18.0.79.10 18.0.80.6 |
| Plesk for Windows | Not affected | Not applicable |
Impact
Arbitrary code execution as root is possible. A Plesk user without elevated privileges could gain full control of the server.
Call to Action
Update to Plesk Obsidian to 18.0.79.10 or 18.0.80.6 or later: How to update Plesk Obsidian to the latest build
How to confirm the patched version is installed
The version shown should be Plesk Obsidian 18.0.79.10 or 18.0.80.6 or later: How to find version of Plesk installed on server?
Comments
if something is going wrong with update how to revert back ?
how to make a backup of existing plesk ?
Is it related to this? https://support.plesk.com/hc/en-us/articles/43070000520855-Vulnerability-CVE-2026-67397-Arbitrary-code-execution-as-root-in-Plesk
IT ALBSIG Please create a ticket with us and we'll assist you with these questions.
Satanun Siwaporn They're different vulnerabilities. Please upgrade to the latest version to address both.
Please sign in to leave a comment.