Back to Security Advisories
More Information
High
2026-07-22
Security Advisory: Plesk PHP Updater Remote Code Execution
Plesk
AlmaLinux 9
CloudLinux 9
Debian 12
Ubuntu 22.04
A vulnerability in the Plesk PHP Updater allows an authenticated admin to write files outside the intended directory, leading to remote code execution as the psaserv service user.
Affected Versions
Plesk Obsidian 18.0.63 and earlier
Patched Version
Plesk Obsidian 18.0.65
Default Update CMD
yum update -y
Fix Commands
AlmaLinux 9 / CloudLinux 9
plesk installer update --select-product-id plesk plesk sbin packagemng --update
Ubuntu 22.04 / Debian 12
apt update plesk installer update --select-product-id plesk
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System