CVE-2026-68489

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 21:17

Updated : 2026-09-15 14:17


NVD link : CVE-2026-68489

Mitre link : CVE-2026-68489

CVE.ORG link : CVE-2026-68489


JSON object : View

Products Affected

No product.

CWE
CWE-96

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')