CVE-2026-65647
8.7WebPros · Plesk Migrator and Plesk Site Import
An improper symlink resolution vulnerability in Plesk Migrator and Site Import extensions allows authenticated users to execute arbitrary code as the root user.
Executive summary
A high-severity vulnerability in Plesk extensions allows authenticated users to escalate privileges and execute arbitrary code as root through symlink manipulation.
Vulnerability
The flaw involves improper symlink resolution during file access operations. An authenticated user can leverage this to trick the system into performing operations on unauthorized files, resulting in root-level code execution.
Business impact
By enabling an attacker to gain root-level access, this vulnerability poses a severe threat to the entire server environment. This could lead to total system compromise, unauthorized access to all hosted websites, and potential data exfiltration, justifying the high CVSS score of 8.7.
Remediation
Immediate Action: Update the Plesk Migrator extension to version 2.36.0 and the Plesk Site Import extension to version 1.12.1 through the Plesk interface.
Proactive Monitoring: Monitor server logs for unusual file system activity or attempts to create symlinks in restricted directories by non-privileged users.
Compensating Controls: Limit access to the Plesk control panel to trusted IP addresses and enforce the principle of least privilege for all administrative and user accounts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Administrators should treat this as a high-priority update. Given the risk of root-level execution, it is imperative to update the affected extensions immediately to prevent privilege escalation by potentially malicious internal or compromised user accounts.