ext: migrator
ext: siteimport
kb: security
kb: ai-created
Situation
A security vulnerability CVE-2026-65647 was discovered in Plesk's Site Import and Migrator extensions that could allow an unprivileged Plesk user to execute arbitrary code with root privileges on the server.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk Migrator | 2.35.0 and earlier | 2.36.0 |
| Site Import | 1.12.0 and earlier | 1.12.1 |
Impact
Local privilege escalation is possible. A Plesk user with an unprivileged hosting subscription on the server may be able to execute arbitrary code with root privileges.
The issue does not depend on a particular server configuration. Any server running an affected version is affected.
In shared and multi-tenant hosting environments, a successful escalation gives the attacker administrative control of the server and access to all subscriptions hosted on it.
Call to action
- The issue is fixed in Plesk Migrator 2.36.0 and Site Import 1.12.1.
- Update the extensions to apply the fix.
Comments
Well maybe i'm N=1, but I tested on random servers of us. But 2.35 is the latest version here! Checked with GUI and CLI
Same here. No updates at all… Also no command to force updates e.g. to 2.36.x.
Sure let's do 100 servers by the interface… Haha.
plesk daily -f UpgradeExtensions -i
Easier…
Any update Vladislav Dratsov ?
Both ‘plesk bin extension --upgrade panel-migrator’ and ‘plesk daily -f UpgradeExtensions’ don't update anything while saying: The extension was successfully upgraded.
I have checked a couple of random servers of us, but they all have the same behaviour!
Please sign in to leave a comment.