Description
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
Published: 2026-09-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Arbitrary Code Execution as Root
Action: Immediate Patch
AI Analysis

Impact

A path traversal weakness (CWE‑22) in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 permits a local user to manipulate file paths to read or write files outside the intended directories. Based on the description, it is inferred that the attacker can place malicious code in a location that Plesk will execute, allowing arbitrary code execution with root privileges. The result is a full compromise of confidentiality, integrity, and availability for the affected host.

Affected Systems

The vulnerability affects installations of Plesk by WebPros. All releases up to and including 18.0.79.9 and those from 18.0.80 through 18.0.80.5 are impacted.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack vector is local: a user who can log onto the system or otherwise obtain local access must exploit the path traversal to gain root‑level code execution. No remote exploitation path is documented in the available data.

Generated by OpenCVE AI on September 4, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Plesk to a patched release newer than 18.0.80.5 to eliminate the path traversal issue.
  • Restrict local user accounts to the least privileges required and disable any unnecessary administrative rights.
  • If an upgrade cannot be performed immediately, isolate the vulnerable directories on the filesystem and deny execution of files from those directories for local users.

Generated by OpenCVE AI on September 4, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Root-level code execution via path traversal in Plesk 18.0.80

Fri, 04 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros plesk
Vendors & Products Webpros
Webpros plesk

Fri, 04 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-04T19:47:09.558Z

Reserved: 2026-07-29T15:00:02.293Z

Link: CVE-2026-67397

cve-icon Vulnrichment

Updated: 2026-09-04T19:47:05.586Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T00:17:13.437

Modified: 2026-09-08T19:42:33.167

Link: CVE-2026-67397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T03:00:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')