CVE-2026-67397

Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

  • Published Sep 4, 2026
  • CVSS 8.5 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-67397 at the National Vulnerability Database