OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-68492

HIGH · CVSS 8.7 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

An untrusted search path vulnerability in Plesk allows remote authenticated users to execute arbitrary code with root privileges through the Plesk RESTful API extension. This poses a significant risk, as it can lead to unauthorized access and control over affected systems. Organizations using Plesk versions prior to 18.0.80.8 and 18.0.81.1 should prioritize patching to mitigate this high-severity threat.

CVE
CVE-2026-68492
Severity
HIGH
CVSS
8.7
EPSS
0.38%

Original NVD Description

An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.