Situation
A security vulnerability allowing local privileges escalation was discovered in the Node.js Toolkit and Ruby Plesk extensions. This security vulnerability has been identified as CVE-2026-68489.
Affected product version
| Product / Component | Affected versions | Patched versions |
|---|---|---|
Ruby extension on Plesk for Linux |
1.6.5 and earlier |
1.6.6 |
Node.js Toolkit extension on Plesk for Linux |
2.4.11 and earlier |
2.5.0 |
Plesk for Windows |
Not affected |
Not applicable |
Impact
Local privilege escalation (LPE) is possible. A Plesk user can execute arbitrary commands as the root user and take full control of the Plesk server.
Call to action
Update the Node.js Toolkit extension to version 2.5.0 or later, and the Ruby extension to 1.6.6 or later. See How to manage Plesk extensions (install, disable, remove, update) for the update steps.
How to confirm the patched version is installed
Go to Extensions > My Extensions and check the version shown for each extension. It should be Node.js Toolkit 2.5.0 or later, and Ruby 1.6.6 or later.
Mitigation
Apply this mitigation only if you cannot update the extensions right now. It is a temporary workaround, not the fix.
- Log in to Plesk as the administrator.
- Go to Service Plans and open each service plan that is in use.
- On the Permissions tab, disable both "Node.js support management" and "Ruby support management" permissions.
- Alternatively, remove the Node.js Toolkit and/or Ruby extensions under Extensions > My Extensions until the patched versions can be installed.
Note: Removing the extensions stops Node.js Toolkit/Ruby applications hosted on the server from working.
Comments
Please sign in to leave a comment.