Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.plesk.com/hc/en-us/articles/43644058632983 |
|
Thu, 24 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros plesk Webpros plesk Extension "plesk Restful Api" |
|
| Vendors & Products |
Webpros
Webpros plesk Webpros plesk Extension "plesk Restful Api" |
Wed, 23 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Untrusted Search Path in Plesk RESTful API Allows Remote Execution as Root |
Wed, 23 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7. | |
| Weaknesses | CWE-426 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-24T14:28:36.450Z
Reserved: 2026-07-30T15:00:00.609Z
Link: CVE-2026-68492
Updated: 2026-09-24T14:28:33.161Z
Status : Awaiting Analysis
Published: 2026-09-23T20:17:13.583
Modified: 2026-09-24T21:16:28.120
Link: CVE-2026-68492
No data.
OpenCVE Enrichment
Updated: 2026-09-24T09:09:15Z