CVE-2026-68489
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.37%
- CWE
- CWE-96
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- WebPros Plesk extension "Ruby"
- WebPros Plesk extension "Node.js Toolkit"
Weakness type
Related vulnerabilities
- CVE-2024-55877 — XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2020-6144 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh
- CVE-2020-6143 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh
- CVE-2024-55662 — XWiki allows remote code execution through the extension sheet
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2022-43938 — Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')