Impact
A local privilege escalation flaw arises from an OS command injection vulnerability in Plesk for Linux, affecting all versions from 18.0.34 up to and including 18.0.79.9 and 18.0.80.5. The flaw can be exploited by a customer or reseller who already has shell access, or who is allowed to modify their own shell setting, allowing them to execute arbitrary commands with root privileges on the host server.
Affected Systems
The vulnerability impacts installations of Plesk for Linux shipped in versions 18.0.34 through 18.0.79.9 and the 18.0.80.5 release. Any Plesk server running these versions is susceptible, regardless of hosting plan.
Risk and Exploitability
The vulnerability carries a CVSS score of 9, indicating critical severity, but its EPSS score is not available and it is not yet listed in the CISA KEV catalog. Exploitation requires local access with an account that has shell privileges or the ability to change shell settings; thus an attacker must already be authenticated to the control panel. Once the local shell is compromised, the attacker can gain full root control, bypassing all isolation measures provided by Plesk.
OpenCVE Enrichment