Junglewise Threat Intelligence

CVE-2026-67394: Plesk for Linux privilege escalation via OS command injection

CVE-2026-67394 · Severity: info · Published 2026-09-01

Executive brief

Plesk is a widely-used hosting control panel that manages web servers, email, and customer accounts on Linux systems. A critical vulnerability allows customers or resellers with shell access to execute arbitrary commands as the root user, gaining complete control over the hosting server and all customer data it contains.

Technical details

This is a local privilege escalation vulnerability in Plesk for Linux, rooted in OS command injection. The vulnerable component allows shell-accessible users (customers or resellers with shell permissions enabled) to inject operating system commands that are executed with root privileges. The attack requires local shell access or the ability to enable shell access on the account. Successful exploitation results in complete system compromise with root-level code execution, potentially exposing all customer data and hosted applications. The vulnerability affects Plesk versions 18.0.34 through 18.0.79.9 and up to 18.0.80.5; updates are available in later patch releases.

Affected products

  • Plesk Plesk for Linux 18.0.34 before 18.0.79.9 and before 18.0.80.5

Timeline

  • 2026-09-01: disclosed

References