Executive brief
Plesk, a widely-used hosting control panel for managing web servers and customer accounts, contains a path traversal vulnerability that allows local users to execute arbitrary code with root privileges. An attacker with local access to a Plesk server could exploit this flaw to gain complete control of the system, compromise all hosted websites and customer data, and use the server as a platform for further attacks.
Technical details
The vulnerability is a path traversal flaw in Plesk versions 18.0.79.9 and earlier, and 18.0.80 through 18.0.80.5. A local user can manipulate file paths to bypass directory restrictions and execute arbitrary code with root-level privileges. The attack requires local access to the Plesk server; no network exploitation is possible. Successful exploitation results in complete system compromise with root-level code execution. Patches addressing this vulnerability are available for affected versions.
Affected products
- Plesk Plesk 18.0.79.9 and earlier, 18.0.80 through 18.0.80.5
Timeline
- 2026-09-04: disclosed