Articles in this section

Vulnerability CVE-2026-65647 in Plesk's Site Import and Migrator extensions

ext: migrator ext: siteimport kb: security kb: ai-created

Situation

A security vulnerability CVE-2026-65647 was discovered in Plesk's Site Import and Migrator extensions that could allow an unprivileged Plesk user to execute arbitrary code with root privileges on the server.

Affected product version

Product Affected versions Patched versions
Plesk Migrator 2.35.0 and earlier 2.36.0
Site Import 1.12.0 and earlier 1.12.1

Impact

Local privilege escalation is possible. A Plesk user with an unprivileged hosting subscription on the server may be able to execute arbitrary code with root privileges.

The issue does not depend on a particular server configuration. Any server running an affected version is affected.

In shared and multi-tenant hosting environments, a successful escalation gives the attacker administrative control of the server and access to all subscriptions hosted on it.

Call to action

  1. The issue is fixed in Plesk Migrator 2.36.0 and Site Import 1.12.1.
  2. Update the extensions to apply the fix.
Was this article helpful?

Comments

4 comments
Date Votes
  • Well maybe i'm N=1, but I tested on random servers of us. But 2.35 is the latest version here! Checked with GUI and CLI

    1
  • Same here. No updates at all… Also no command to force updates e.g. to 2.36.x.

    1
  • Sure let's do 100 servers by the interface… Haha.

    plesk daily -f UpgradeExtensions -i

    Easier…

    0
  • Any update Vladislav Dratsov  ?

    Both ‘plesk bin extension --upgrade panel-migrator’ and ‘plesk daily -f UpgradeExtensions’ don't update anything while saying: The extension was successfully upgraded.
     

    I have checked a couple of random servers of us, but they all have the same behaviour!

     

    0

Please sign in to leave a comment.