Plesk - remote authenticated users to execute arbitrary code as root
Situation
A security vulnerability CVE-2026-68492 was discovered in Plesk for Linux. It allows remote authenticated users to execute arbitrary code as root via the Plesk RESTful API extension.
Affected product version
Product / Component
Plesk for Linux
Affected versions
18.0.34 - 18.0.80.7
18.0.81.0
Patched versions
18.0.80.8
18.0.81.1
Plesk versions before 18.0.34 and Plesk RESTful API versions before 2.4.2 are not affected.
Impact
A remote authenticated user can execute arbitrary code as root via the Plesk RESTful API extension.
The Plesk RESTful API extension is installed by default, although it is hidden in the Plesk interface. A server may therefore be affected even if the extension was not installed manually.
The vulnerability requires an affected version of both products at the same time: Plesk and the Plesk RESTful API extension. The extension is normally updated automatically. Confirm that version 2.4.7 or later is installed.
Meet Nix and Bruce @ https://twobirdsonelesbox.com
My project/stuff page @ https://serveraddict.net



