SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-68489

HIGH · CVSS 8.7 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Plesk extensions "Ruby" prior to version 1.6.6 and "Node.js Toolkit" prior to version 2.5.0 are vulnerable to static code injection, enabling remote authenticated users to execute arbitrary code with root privileges through custom environment variables. This high-severity vulnerability poses a significant risk to systems utilizing these extensions, particularly in environments where user authentication is not adequately controlled. Administrators of affected Plesk installations should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-68489
Severity
HIGH
CVSS
8.7
EPSS
0.37%

Original NVD Description

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.