Loading market data...
← Back to CVE feed

CVE-2026-68489

UNKNOWN View on NVD ↗

Description

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.

Published: Sep 14, 2026 21:17 UTC Modified: Sep 15, 2026 14:17 UTC