Situation
A security vulnerability CVE-2026-87898 was discovered in Plesk's Site Import extension. A database name submitted during an import is not quoted as data before it is used in a command that runs with root privileges, which allows command injection.
Affected product version
| Product / Component | Affected versions | Patched versions |
|---|---|---|
Site Import extension on Plesk for Linux |
1.12.1 and earlier |
1.12.2 |
Plesk for Windows |
Not affected |
Not applicable |
Impact
Arbitrary code execution as root is possible. A Plesk customer without elevated privileges can run commands as the root user on the Plesk server.
This can expose other subscriptions, databases, credentials, and the configuration of the server.
Call to action
Update the Site Import extension to version 1.12.2 or later. See How to manage Plesk extensions (install, disable, remove, update) for the update steps.
How to confirm the patched version is installed
Go to Extensions > My Extensions and check the version shown for each extension. It should be Site Import 1.12.2 or later.
Comments
Please sign in to leave a comment.