Retour à la veille

CVE-2026-68489

Publié : 14 septembre 2026
Modifié : 18 septembre 2026
Lien officiel NVD

Description détaillée

Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.

Références et Patchs