Plesk has released a hotfix for CVE-2026-67394, a critical local privilege-escalation vulnerability in Plesk for Linux. A customer or reseller account with shell access—or permission to change its own shell access—may be able to gain root control of the server.
Plesk for Windows is not affected. Linux servers in the affected version ranges should be updated immediately, especially multi-tenant systems where customers or resellers can use SSH.
Affected and patched versions
| Product | Affected versions | Patched version |
|---|---|---|
| Plesk for Linux 18.0.34–18.0.79 | 18.0.34 through 18.0.79.8 | 18.0.79.9 or later |
| Plesk for Linux 18.0.80 | 18.0.80 through 18.0.80.4 | 18.0.80.5 or later |
| Plesk for Windows | Not affected | Not applicable |
The official Plesk CVE-2026-67394 advisory was updated on 27 August 2026.
Check your installed Plesk build
Connect as root and run:
plesk version
A server on the 18.0.79 branch must report 18.0.79.9 or later. A server on the 18.0.80 branch must report 18.0.80.5 or later.
You can also verify the version in Tools & Settings > Server Components.
Install the Plesk hotfix
Take a current backup, then install the latest microupdate from Tools & Settings > Updates and Upgrades. From the command line, the standard Plesk installer can update installed components:
plesk installer --select-release-latest --upgrade-installed-components
After the update completes, run plesk version again and compare the reported build with the patched versions above.
Temporary mitigation when shell access is not required
For each affected subscription or webspace, open Domains > example.com > Hosting Settings and set Shell access to the server to Forbidden. Apply the equivalent restriction at the customer or reseller webspace level where appropriate.
Verify the effective account configuration on the server rather than assuming that a panel-level change removed an existing login shell. Re-enable access only after the fixed Plesk build is installed and confirmed.
What to review after patching
Because successful exploitation grants root-level control, patching alone is not enough if the server may have been attacked. Review:
- customer and reseller accounts that had shell access or could change it;
- successful and failed SSH logins around the exposure period;
- unexpected
rootSSH keys, sudoers entries, users, and groups; - unfamiliar cron jobs, systemd services, startup scripts, and listening processes;
- unexplained changes under Plesk system directories and hosted subscriptions.
If you identify suspicious privileged activity, isolate the host, preserve logs and disk evidence, rotate credentials from a trusted system, and consider rebuilding from known-good sources.
What is CVE-2026-67394?+
Which Plesk versions fix CVE-2026-67394?+
Is Plesk for Windows affected?+
Can I mitigate the issue without updating?+
Next steps
- Plesk CVE-2026-65646, 65642, and 65647: patch your server
- Configure the Plesk Firewall extension
- Plesk license tiers explained
A current Plesk license keeps supported installations eligible for vendor microupdates and security fixes.