{"id":"CVE-2026-68489","title":"Static Code Injection in Plesk extensions \"Ruby\" before 1.6.6 and \"Node.js Toolkit\" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.","summary":"Static Code Injection in Plesk extensions \"Ruby\" before 1.6.6 and \"Node.js Toolkit\" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-96"],"vendor":"WebPros","product":"Plesk extension \"Ruby\"","affected":["plesk_extension_ruby < 1.6.6","plesk_extension_node.js_toolkit < 2.5.0"],"published":"2026-09-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:34:36.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68489","references":[{"url":"https://support.plesk.com/hc/en-us/articles/43473204617239","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"epss":0.00398,"epssPercentile":0.33744,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T13:28:42.978491Z"},"cvssSource":"cna","ingestedAt":"2026-09-14T21:15:17.461Z","slug":"CVE-2026-68489","body":"## Overview\n\nStatic Code Injection in Plesk extensions \"Ruby\" before 1.6.6 and \"Node.js Toolkit\" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}