Page 1 of 1

CVE-2026-68489 - Plesk Extensions Ruby and Node.js Toolkit Static Code Injection

Posted: Mon Sep 14, 2026 11:39 pm
by Starburst-David
CVE ID :CVE-2026-68489
Published : Sept. 14, 2026, 9:17 p.m. | 44 minutes ago
Description :Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Severity: 8.7 | HIGH

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-68489