Articles in this section

Vulnerability CVE-2026-68489: Arbitrary code execution as root in Plesk's Node.js Toolkit and Ruby extensions

kb: security kb: ai-created

Situation

A security vulnerability allowing local privileges escalation was discovered in the Node.js Toolkit and Ruby Plesk extensions. This security vulnerability has been identified as CVE-2026-68489.

Affected product version

Product / Component Affected versions Patched versions

Ruby extension on Plesk for Linux

1.6.5 and earlier

1.6.6

Node.js Toolkit extension on Plesk for Linux

2.4.11 and earlier

2.5.0

Plesk for Windows

Not affected

Not applicable

Impact

Local privilege escalation (LPE) is possible. A Plesk user can execute arbitrary commands as the root user and take full control of the Plesk server.

Call to action

Update the Node.js Toolkit extension to version 2.5.0 or later, and the Ruby extension to 1.6.6 or later. See How to manage Plesk extensions (install, disable, remove, update) for the update steps.

How to confirm the patched version is installed

Go to Extensions > My Extensions and check the version shown for each extension. It should be Node.js Toolkit 2.5.0 or later, and Ruby 1.6.6 or later.

Mitigation

Apply this mitigation only if you cannot update the extensions right now. It is a temporary workaround, not the fix.

  1. Log in to Plesk as the administrator.
  2. Go to Service Plans and open each service plan that is in use.
  3. On the Permissions tab, disable both "Node.js support management" and "Ruby support management" permissions.
  4. Alternatively, remove the Node.js Toolkit and/or Ruby extensions under Extensions > My Extensions until the patched versions can be installed.

Note: Removing the extensions stops Node.js Toolkit/Ruby applications hosted on the server from working. 

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.