Articles in this section

Vulnerability CVE-2026-87898: Arbitrary code execution as root in Plesk's Site Import extension

kb: security kb: ai-created

Situation

A security vulnerability CVE-2026-87898 was discovered in Plesk's Site Import extension. A database name submitted during an import is not quoted as data before it is used in a command that runs with root privileges, which allows command injection.

Affected product version

Product / Component Affected versions Patched versions

Site Import extension on Plesk for Linux

1.12.1 and earlier

1.12.2

Plesk for Windows

Not affected

Not applicable

Impact

Arbitrary code execution as root is possible. A Plesk customer without elevated privileges can run commands as the root user on the Plesk server.

This can expose other subscriptions, databases, credentials, and the configuration of the server.

Call to action

Update the Site Import extension to version 1.12.2 or later. See How to manage Plesk extensions (install, disable, remove, update) for the update steps.

How to confirm the patched version is installed

Go to Extensions > My Extensions and check the version shown for each extension. It should be Site Import 1.12.2 or later.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.