CVE-2026-68492 Overview
CVE-2026-68492 is an untrusted search path vulnerability [CWE-426] affecting Plesk installations that use the Plesk RESTful API extension. The flaw exists in Plesk versions from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1, when running the Plesk RESTful API extension from 2.4.2 before 2.4.7. Remote authenticated users can leverage the untrusted search path to execute arbitrary code with root privileges on the underlying host. The vulnerability transforms a low-privilege authenticated session into full system compromise of the Plesk server.
Critical Impact
Authenticated attackers can achieve arbitrary code execution as root on affected Plesk hosts through the RESTful API extension.
Affected Products
- Plesk 18.0.34 through versions before 18.0.80.8
- Plesk 18.0.81 before 18.0.81.1
- Plesk RESTful API extension 2.4.2 before 2.4.7
Discovery Timeline
- 2026-09-23 - CVE-2026-68492 published to the National Vulnerability Database
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-68492
Vulnerability Analysis
The vulnerability resides in how the Plesk RESTful API extension resolves paths to executable components or libraries at runtime. Because the extension runs with elevated privileges within the Plesk management stack, any attacker-controlled path element gets processed in a root execution context. An authenticated Plesk user who can influence the search path or place files in a searched location can substitute a malicious binary or library. The extension then loads or executes the attacker-supplied artifact instead of the intended component.
Root Cause
The root cause is an untrusted search path condition [CWE-426]. The Plesk RESTful API extension does not sufficiently restrict or validate the directories consulted when locating executables or shared objects. Untrusted directories are traversed before or alongside trusted system paths, allowing precedence-based hijacking of resolved binaries.
Attack Vector
Exploitation requires network access to the Plesk management interface and valid authentication as a Plesk user. The attacker interacts with the RESTful API surface exposed by the vulnerable extension to trigger the vulnerable code path. Because the extension performs privileged operations, the attacker-controlled component executes as root, providing complete control over the Plesk host, hosted websites, databases, and customer data.
No verified proof-of-concept code is publicly available. See the Plesk Support Article for vendor technical details.
Detection Methods for CVE-2026-68492
Indicators of Compromise
- Unexpected binaries or shared object files appearing in directories writable by Plesk users or panel subscribers.
- Processes spawned by the Plesk RESTful API extension executing from non-standard filesystem locations.
- New or modified root-owned files, cron entries, or systemd units created shortly after RESTful API requests.
- Outbound network connections initiated by Plesk service accounts to unfamiliar destinations.
Detection Strategies
- Audit installed Plesk and extension versions with plesk version and the extensions catalog to identify hosts within the vulnerable range.
- Inspect Plesk API access logs for authenticated calls to RESTful API endpoints followed by unexpected privilege transitions.
- Baseline the filesystem locations searched by the extension and alert on write events from non-root accounts.
Monitoring Recommendations
- Forward Plesk panel logs, API logs, and host audit logs (auditd, syslog) to a centralized analytics platform for correlation.
- Monitor execve calls for the RESTful API extension processes and flag executions that resolve outside standard system paths.
- Track integrity of extension binaries and libraries with file integrity monitoring to detect substitution.
How to Mitigate CVE-2026-68492
Immediate Actions Required
- Upgrade Plesk to 18.0.80.8 or later on the 18.0.x branch, or to 18.0.81.1 or later on the 18.0.81 branch.
- Update the Plesk RESTful API extension to version 2.4.7 or later on every affected host.
- Rotate credentials for all Plesk panel users and any API tokens issued while vulnerable versions were in use.
- Review privileged accounts and hosted services for post-exploitation artifacts such as new users, SSH keys, and scheduled tasks.
Patch Information
Plesk has released fixed versions that address the untrusted search path condition. Apply Plesk 18.0.80.8 (or newer) or 18.0.81.1 (or newer) together with Plesk RESTful API extension 2.4.7 or later. Refer to the Plesk Support Article for release specifics and upgrade procedures.
Workarounds
- Uninstall or disable the Plesk RESTful API extension until the fixed extension version can be deployed.
- Restrict panel authentication to trusted administrators and enforce multi-factor authentication to reduce the pool of users who can trigger the flaw.
- Limit network exposure of the Plesk management interface by placing it behind a VPN or IP allowlist.
# Verify Plesk and extension versions, then apply updates
plesk version
plesk bin extension --list | grep -i restful
# Apply Plesk updates via the built-in updater
plesk installer update
# Update the RESTful API extension to a fixed version (2.4.7+)
plesk bin extension --upgrade rest-api
# Temporary mitigation: disable the extension until patched
plesk bin extension --disable rest-api
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.