Back to Security Advisories

Security Advisory: Plesk PHP Updater Remote Code Execution

A vulnerability in the Plesk PHP Updater allows an authenticated admin to write files outside the intended directory, leading to remote code execution as the psaserv service user.

High
Plesk AlmaLinux 9 CloudLinux 9 Debian 12 Ubuntu 22.04

Affected Versions

Plesk Obsidian 18.0.63 and earlier

Patched Version

Plesk Obsidian 18.0.65

Default Update CMD

yum update -y

Fix Commands

AlmaLinux 9 / CloudLinux 9

plesk installer update --select-product-id plesk
plesk sbin packagemng --update

Ubuntu 22.04 / Debian 12

apt update
plesk installer update --select-product-id plesk

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System