Panellicense

CVE-2026-67394: patch the Plesk root privilege-escalation flaw

CVE-2026-67394 can let a Plesk customer or reseller with shell access gain root control of a Linux server. Update to 18.0.79.9, 18.0.80.5, or later.

pleskcvesecuritylinuxshellroot
schema: TechArticleschema: FAQPageschema: BreadcrumbList

Plesk has released a hotfix for CVE-2026-67394, a critical local privilege-escalation vulnerability in Plesk for Linux. A customer or reseller account with shell access—or permission to change its own shell access—may be able to gain root control of the server.

Plesk for Windows is not affected. Linux servers in the affected version ranges should be updated immediately, especially multi-tenant systems where customers or resellers can use SSH.

Affected and patched versions

ProductAffected versionsPatched version
Plesk for Linux 18.0.34–18.0.7918.0.34 through 18.0.79.818.0.79.9 or later
Plesk for Linux 18.0.8018.0.80 through 18.0.80.418.0.80.5 or later
Plesk for WindowsNot affectedNot applicable

The official Plesk CVE-2026-67394 advisory was updated on 27 August 2026.

Check your installed Plesk build

Connect as root and run:

plesk version

A server on the 18.0.79 branch must report 18.0.79.9 or later. A server on the 18.0.80 branch must report 18.0.80.5 or later.

You can also verify the version in Tools & Settings > Server Components.

Install the Plesk hotfix

Take a current backup, then install the latest microupdate from Tools & Settings > Updates and Upgrades. From the command line, the standard Plesk installer can update installed components:

plesk installer --select-release-latest --upgrade-installed-components

After the update completes, run plesk version again and compare the reported build with the patched versions above.

Temporary mitigation when shell access is not required

For each affected subscription or webspace, open Domains > example.com > Hosting Settings and set Shell access to the server to Forbidden. Apply the equivalent restriction at the customer or reseller webspace level where appropriate.

Verify the effective account configuration on the server rather than assuming that a panel-level change removed an existing login shell. Re-enable access only after the fixed Plesk build is installed and confirmed.

What to review after patching

Because successful exploitation grants root-level control, patching alone is not enough if the server may have been attacked. Review:

  • customer and reseller accounts that had shell access or could change it;
  • successful and failed SSH logins around the exposure period;
  • unexpected root SSH keys, sudoers entries, users, and groups;
  • unfamiliar cron jobs, systemd services, startup scripts, and listening processes;
  • unexplained changes under Plesk system directories and hosted subscriptions.

If you identify suspicious privileged activity, isolate the host, preserve logs and disk evidence, rotate credentials from a trusted system, and consider rebuilding from known-good sources.

What is CVE-2026-67394?+
It is a Plesk for Linux vulnerability that may let a customer or reseller with shell access, or permission to change its own shell access, escalate privileges to root.
Which Plesk versions fix CVE-2026-67394?+
Use Plesk Obsidian 18.0.79.9, 18.0.80.5, or a later supported build.
Is Plesk for Windows affected?+
No. Plesk's advisory lists Plesk for Windows as not affected.
Can I mitigate the issue without updating?+
Only when customer and reseller shell access is unnecessary: set it to Forbidden while arranging the update. Plesk states that no mitigation is available when shell access must remain enabled.

Next steps

A current Plesk license keeps supported installations eligible for vendor microupdates and security fixes.

changelog
Plesk CVE-2026-65646, 65642, and 65647: patch your server
Three critical Plesk flaws expose server files, customer databases, and root access. Check the affected builds and update Plesk plus both extensions.
3 min read
changelog
CVE-2026-65643: patch the cPanel domain parking root vulnerability
CVE-2026-65643 lets an authenticated cPanel user with parked or addon-domain access create arbitrary server files and potentially execute code as root. Check the fixed builds and update now.
3 min read
how to
Configure Plesk Fail2Ban jails to stop brute-force attacks
Enable Plesk's Fail2Ban, tune the default jails, whitelist your own IPs, and fix the silent failures where bans show in the panel but never reach iptables.
7 min read
how to
Set up the Plesk Firewall extension without locking yourself out
Enable the Plesk Firewall extension, open the right ports, write custom allow/deny rules by IP and country, and use the 60-second rollback so a bad rule never strands you.
7 min read
changelog
RtabRace (CVE-2026-68138): mitigating the kernel race on CloudLinux
A traffic-control race in the Linux kernel lets any shell user panic a shared server on demand. CloudLinux 8 and 7 Hybrid need the sysctl mitigation today — here's the command and the patch status.
5 min read
changelog
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
7 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.