---
id: CVE-2026-68492
title: >-
  An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8
  and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute
  arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before
  2.4.7.
summary: >-
  An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8
  and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute
  arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before
  2.4.7.
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-426
vendor: WebPros
product: Plesk
affected:
  - Plesk >= 18.0.34 < 18.0.80.8
  - Plesk >= 18.0.81 < 18.0.81.1
  - plesk_extension_plesk_restful_api >= 2.4.2 < 2.4.7
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:16:28.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68492'
references:
  - url: 'https://support.plesk.com/hc/en-us/articles/43644058632983'
    label: support@hackerone.com
tags:
  - nvd
  - cve.org
epss: 0.00354
epssPercentile: 0.26525
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T14:28:28.100954Z'
cvssSource: cna
ingestedAt: '2026-09-23T20:32:10.749Z'
---

## Overview

An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
