CVE-2026-68489
8.7WebPros · Plesk extensions Ruby and Node.js Toolkit
A static code injection vulnerability in Plesk extensions allows authenticated users to execute arbitrary code as root via manipulated environment variables.
Executive summary
A critical static code injection vulnerability in Plesk Ruby and Node.js Toolkit extensions allows authenticated remote attackers to achieve full root-level code execution.
Vulnerability
This is a static code injection flaw (CWE-96) where the application improperly neutralizes directives. An authenticated user can trigger this vulnerability by injecting custom environment variables, which the system then executes with root privileges.
Business impact
The ability for an authenticated user to execute arbitrary code as root poses a catastrophic risk to the integrity and confidentiality of the entire server. Given the CVSS score of 8.7, this vulnerability is classified as High, reflecting the potential for total system compromise, unauthorized data access, and the ability of an attacker to pivot into other hosted applications or services.
Remediation
Immediate Action: Update the Plesk "Ruby" extension to version 1.6.6 or later and the "Node.js Toolkit" extension to version 2.5.0 or later via the Plesk extension manager.
Proactive Monitoring: Review web server and system authentication logs for suspicious environment variable configurations or unexpected process execution patterns initiated by non-privileged service accounts.
Compensating Controls: While a patch is available, ensure that administrative access to the Plesk control panel is restricted to trusted internal networks and utilize strong multi-factor authentication to limit the risk of an attacker gaining the required authenticated access.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available in the provided data.
Analyst recommendation
The severity of this vulnerability, combined with the attainment of root-level privileges, requires that administrators prioritize these updates immediately. Organizations should verify their current extension versions through the Plesk dashboard and apply the vendor-supplied patches to prevent potential privilege escalation and full system compromise.
More WebPros CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by d1n4h, per the CVE Program record.