Skip to content
ThreatCluster

Critical Plesk Vulnerability Allows Arbitrary Command Execution

First seen 1 Jun 2026, 21:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 2, 2026 at 21:06 UTC
  • CVE-2026-44962 allows low-privileged users to execute arbitrary commands on Plesk servers.
  • The vulnerability is linked to improper input handling in the APS Application Catalog.
  • Affected systems include all versions of Plesk for Linux utilizing the vulnerable component.

A critical vulnerability in Plesk, tracked as CVE-2026-44962, was disclosed on May 29, 2026. This flaw enables authenticated low-privileged users to execute arbitrary operating system commands on affected servers. The vulnerability is linked to improper input handling in the APS Application Catalog component of Plesk for Linux. Security researchers have raised alarms about the potential for exploitation, which could lead to significant impacts on server integrity and data security. The issue has been documented in both the National Vulnerability Database and GitHub Advisory Database. Administrators are urged to assess their systems for this vulnerability and apply necessary mitigations. The scope of impact includes all versions of Plesk that utilize the affected component.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 105d ago How this analysis works

Timeline

2026-05-29
CVE-2026-44962 published
A critical vulnerability in Plesk was disclosed, allowing command execution by low-privileged users.
Cybersecuritynews
2026-06-01
Security concerns raised
Researchers confirmed the vulnerability's potential for exploitation, urging immediate attention from administrators.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track CVE-2026-44962 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed