Description
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Static Code Injection in Plesk extensions "Ruby" and "Node.js Toolkit" allows a remote authenticated user to inject code into the execution environment. By setting custom environment variables, the attacker can cause the vulnerable helper process to interpret untrusted input as code. The result is arbitrary code execution running with root privileges on the host system, which can lead to full system compromise, data exfiltration, or persistence mechanisms.

Affected Systems

The vulnerability affects the WebPros Plesk extensions "Ruby" versions prior to 1.6.6 and "Node.js Toolkit" versions prior to 2.5.0. No other vendors or products are listed in the CNA data. Users deploying these extensions on a Plesk server are at risk unless the extensions are updated.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score is unavailable, but the lack of a KEV listing does not mitigate the risk; exploit code could still be crafted by attackers with authenticated access. The attack vector is inferred to be a remote authenticated user who can set environment variables within the context of the Plesk server, a common user role for administrators or plugin owners. The attacker’s ability to execute code as root makes exploitation extremely damaging.

Generated by OpenCVE AI on September 15, 2026 at 10:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Plesk Ruby extension to version 1.6.6 or newer and the Node.js Toolkit extension to version 2.5.0 or newer.
  • Disable or restrict the ability to set custom environment variables for these extensions through server configuration or security policies.
  • Limit administrative privileges to trusted users and monitor for anomalous environment variable usage or unexpected code execution.

Generated by OpenCVE AI on September 15, 2026 at 10:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Ruby: Node.js Toolkit: Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection
Weaknesses CWE-94
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Weaknesses CWE-96
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-15T13:28:53.581Z

Reserved: 2026-07-30T15:00:00.609Z

Link: CVE-2026-68489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:25.567

Modified: 2026-09-14T21:17:25.567

Link: CVE-2026-68489

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T20:53:05Z

Links: CVE-2026-68489 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:15:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')

  • CWE-96

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')