Articles in this section

Vulnerability CVE-2026-65647 in Plesk's Site Import and Migrator extensions

ext: migrator ext: siteimport kb: security kb: ai-created

Situation

A security vulnerability CVE-2026-65647 was discovered in Plesk's Site Import and Migrator extensions that could allow an unprivileged Plesk user to execute arbitrary code with root privileges on the server.

Affected product version

Product Affected versions Patched versions
Plesk Migrator 2.35.0 and earlier 2.36.0
Site Import 1.12.0 and earlier 1.12.1

Impact

Local privilege escalation is possible. A Plesk user with an unprivileged hosting subscription on the server may be able to execute arbitrary code with root privileges.

The issue does not depend on a particular server configuration. Any server running an affected version is affected.

In shared and multi-tenant hosting environments, a successful escalation gives the attacker administrative control of the server and access to all subscriptions hosted on it.

Call to action

  1. The issue is fixed in Plesk Migrator 2.36.0 and Site Import 1.12.1.
  2. Update the extensions to apply the fix.
Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.