Junglewise Threat Intelligence

CVE-2026-68489: Plesk Ruby and Node.js Toolkit static code injection

CVE-2026-68489 · Severity: info · CVSS 0 · Published 2026-09-14

Vendors: Plesk.

Executive brief

Plesk is a hosting control panel that automates server and website management for hosting providers and enterprises. Two Plesk extensions—Ruby and Node.js Toolkit—allow authenticated users to inject arbitrary code that executes with root privileges, potentially compromising the entire hosting environment and customer data.

Technical details

A static code injection vulnerability exists in Plesk's Ruby extension (before 1.6.6) and Node.js Toolkit extension (before 2.5.0). The vulnerability allows remote authenticated users to execute arbitrary code with root privileges by manipulating custom environment variables. The flaw does not require special privileges beyond authentication to the Plesk control panel, and exploitation results in arbitrary code execution at the system's highest privilege level.

Affected products

  • Plesk Ruby extension before 1.6.6
  • Plesk Node.js Toolkit extension before 2.5.0

Timeline

  • 2026-09-14: disclosed

References