Full Report
WebPros security advisory (AV26-866)
Analysis Summary
# Vulnerability: Plesk Local Privilege Escalation to Root
## CVE Details
- **CVE ID:** CVE-2026-67394
- **CVSS Score:** Not explicitly listed in advisory (Typically High/Critical for Root Escalation)
- **CWE:** Not specified (Likely related to Improper Privilege Management or Path Traversal)
## Affected Systems
- **Products:** WebPros Plesk
- **Versions:**
- Versions prior to 18.0.79.9
- Versions prior to 18.0.80.5
- **Configurations:** Systems running affected versions of Plesk control panel on Linux/Windows environments.
## Vulnerability Description
A vulnerability exists in WebPros Plesk that allows an attacker with existing access to the system to escalate their privileges to the **root** (administrative) level. While specific technical mechanics (such as symlink attacks or insecure file permissions) are not detailed in the brief advisory, the flaw permits a user to bypass intended permission boundaries to gain full control over the host server.
## Exploitation
- **Status:** Not specified as exploited in the wild (based on current advisory data).
- **Complexity:** Low to Medium (Privilege escalation typically requires local account access).
- **Attack Vector:** Local (Requires the attacker to have an existing foothold on the system).
## Impact
- **Confidentiality:** Total (Root access allows full data access).
- **Integrity:** Total (Root access allows modification of all system files).
- **Availability:** Total (Root access allows system shutdown or destruction).
## Remediation
### Patches
WebPros has released updates to address this vulnerability. Users are urged to upgrade to the following versions or later:
- **Plesk 18.0.79.9**
- **Plesk 18.0.80.5**
### Workarounds
No specific manual workarounds were provided. The primary remediation strategy is the application of the official security patches.
## Detection
- **Indicators of Compromise:** Monitor for unusual activity from low-privileged service accounts, unauthorized changes to system-level configuration files, or the unexpected presence of setuid binaries.
- **Detection methods and tools:** Audit system logs for successful `sudo` transitions or calls to Plesk-specific binaries by non-admin users.
## References
- **Vendor Advisory:** hxxps[://]support[.]plesk[.]com/hc/en-us/articles/42968165026967-CVE-2026-67394-Vulnerability-in-Plesk-allows-privilege-escalation-to-root
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/webpros-security-advisory-av26-866