Skip to content
ThreatCluster

Critical Plesk Vulnerability Enables Root Access for Users

First seen 15 Dec 2025, 13:47 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A critical vulnerability in Plesk for Linux, tracked as CVE-2025-66430, allows users to gain root access on affected servers. This flaw, found in the Password-Protected Directories feature, results from improper handling of user input, enabling attackers to inject arbitrary data into Apache configuration files. Web hosting providers and organizations using Plesk are at risk due to this security issue.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 188d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track CVE-2025-66430 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed