CVE-2026-67394 — OS Command Injection in Plesk for Linux Enables Root Privilege Escalation

CVE & Vulnerabilities · September 3, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly disclosed vulnerability in Plesk for Linux, the widely used hosting control panel, lets a customer or reseller with shell access escalate their privileges all the way to root through an OS command injection flaw. It affects every version from 18.0.34 up to just before the 18.0.79.9 and 18.0.80.5 fixes. Since Plesk manages countless shared hosting servers, an exploit here could hand a low-privilege tenant full control of the underlying machine.

// source: nvd.nist.gov ↗

Back to Blog