CVE-2026-68492
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
- Published Sep 23, 2026
- CVSS 8.7 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- WebPros security advisory (AV26-961) Canadian Centre for Cyber Security ·