SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-67394

CRITICAL · CVSS 9 EPSS 1.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical local privilege escalation vulnerability exists in Plesk for Linux, affecting all versions from 18.0.34 up to 18.0.79.9 and 18.0.80.5. This flaw allows users with shell access to execute OS command injection, potentially granting them root access to the hosting server. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and control over their systems.

CVE
CVE-2026-67394
Severity
CRITICAL
CVSS
9
EPSS
1.29%
Linux

Original NVD Description

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.