CVE-2026-68492

8.7

WebPros · Plesk

An untrusted search path vulnerability in the Plesk RESTful API extension allows authenticated remote users to execute arbitrary code with root privileges.

Executive summary

A high-severity untrusted search path vulnerability in WebPros Plesk allows authenticated attackers to gain full root-level code execution.

Vulnerability

This is an untrusted search path flaw (CWE-426) within the Plesk RESTful API extension. Remote authenticated users can leverage this issue to execute arbitrary commands on the underlying host with root privileges.

Business impact

The vulnerability carries a CVSS score of 8.7, reflecting its high impact on system integrity, availability, and confidentiality. Successful exploitation provides an attacker with complete control over the Plesk server, potentially leading to unauthorized data exfiltration, service disruption, or the compromise of all hosted websites and databases.

Remediation

Immediate Action: Update the Plesk core to version 18.0.80.8 or 18.0.81.1, and ensure the Plesk RESTful API extension is updated to version 2.4.7 or later.

Proactive Monitoring: Review system logs for unauthorized command execution or unexpected binary loading events originating from the Plesk API service.

Compensating Controls: Restrict network access to the Plesk RESTful API endpoint to trusted IP addresses only, and implement strict API key management to minimize the risk from compromised user accounts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for full system compromise, administrators must prioritize updating the Plesk platform and the associated RESTful API extension immediately. Organizations should verify that their patching cycle covers both the core software and the specific extension versions identified to ensure complete mitigation of this root-level execution risk.

More WebPros CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Ali Mustafa (rz1027), per the CVE Program record.