CVE-2026-68492
Received
Received - Intake
Untrusted Search Path in Plesk RESTful API Extension
Vulnerability report for CVE-2026-68492, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-23
Last updated on: 2026-09-23
Assigner: HackerOne
Description
Description
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| plesk | plesk | to 18.0.80.8 (exc) |
| plesk | plesk | From 18.0.81 (inc) to 18.0.81.1 (exc) |
| plesk | plesk_restful_api | From 2.4.2 (inc) to 2.4.7 (exc) |
| plesk | plesk | to 18.0.81.1 (exc) |
| plesk | plesk_restful_api_extension | to 2.4.7 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-426 | The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control. |