A particularly dangerous security flaw was recently discovered in Plesk for Linux, causing great concern among the system administrator community and organizations that rely on the platform to manage their infrastructure. The vulnerability could allow ordinary users to gain root access, i.e. complete control of a server, with potentially devastating consequences.

What is CVE-2025-66430 and where is it found?
The vulnerability is listed as CVE-2025-66430 and concerns the “Password-Protected Directories” of Plesk. The root of the problem is found in improper user input handling, which allows the insertion of arbitrary and malicious data into configuration files Apache.
Simply put, a user with basic access to Plesk can "poison" the web server configuration, taking advantage of the incomplete input validation provided by this feature.
See also: Windows RasMan vulnerability allows arbitrary code execution
From a simple user to root with one exploit
The severity of the vulnerability lies in the fact that it allows local privilege escalation. Once malicious data is inserted into Apache files, the attacker can execute commands with root privileges. This means complete control of the system, without requiring a prior compromise at the operating system level.
In such a scenario, the consequences could include data theft or corruption, installation of malware, creation of backdoors , or even lateral movement to other systems on the same network.
Why this is a critical threat to organizations
The ability to escalate privileges from a simple user account to full root access is considered one of the most dangerous categories of vulnerabilities. In web hosting or enterprise application, where many users share the same server, the risk increases exponentially.
Any user with access to the “Password-Protected Directories” feature could, in theory, exploit the vulnerability. This makes the threat particularly critical for hosting providers, MSPs, and organizations with complex Plesk environments.
Which versions are affected?
According to official information, the issue affects Plesk versions 18.0.70 to 18.0.74, while Plesk Onyx. The company has already released patch updates, including micro-releases 18.0.73.5 and 18.0.74.2, which close the specific gap.
See also: Microsoft: 'In Scope by Default' makes all vulnerabilities eligible for bug bounties
Administrators are urged to proceed with an immediate upgrade, as any delay increases the likelihood of exploitation, especially if the vulnerability begins to be actively exploited by malicious actors.

What administrators should do immediately
The first and most critical action is to immediately updates security that Plesk has made available. The official support documentation provides detailed instructions for the upgrade process, depending on the version and configuration of the system.
At the same time, it is recommended to check access rights to the "Password-Protected Directories" function, to ensure that only fully authorized users can use it.
Additional defense and monitoring measures
In addition to installing patches, organizations should increase their monitoring of logs . Suspicious changes to Apache configuration or unusual attempts to execute commands could be an indication of an exploit attempt.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, adopting practical minimum permissions and regularly reviewing security settings can significantly limit the impact of similar vulnerabilities in the future.
See also: CISA added Sierra Wireless Routers vulnerability to KEV List

Another bell for infrastructure management
CVE-2025-66430 is a stark reminder that server management tools, no matter how widespread, are still attractive targets for attackers. In a world where cyberattacks are becoming increasingly sophisticated, timely updates and constant vigilance are not an option, but a necessity.
