ext: migrator
ext: siteimport
kb: security
kb: ai-created
Situation
A security vulnerability CVE-2026-65647 was discovered in Plesk's Site Import and Migrator extensions that could allow an unprivileged Plesk user to execute arbitrary code with root privileges on the server.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk Migrator | 2.35.0 and earlier | 2.36.0 |
| Site Import | 1.12.0 and earlier | 1.12.1 |
Impact
Local privilege escalation is possible. A Plesk user with an unprivileged hosting subscription on the server may be able to execute arbitrary code with root privileges.
The issue does not depend on a particular server configuration. Any server running an affected version is affected.
In shared and multi-tenant hosting environments, a successful escalation gives the attacker administrative control of the server and access to all subscriptions hosted on it.
Call to action
- The issue is fixed in Plesk Migrator 2.36.0 and Site Import 1.12.1.
- Update the extensions to apply the fix.
Comments
Please sign in to leave a comment.