AI analysis
Plesk, the WebPros hosting control panel, resolves symlinks without verifying their targets before file access (CWE-59, link following), so privileged panel operations can be redirected through an attacker-controlled symlink. The flaw is triggered remotely by an authenticated low-privileged user — for example a tenant account on a shared hosting server — who gets Plesk's privileged file operations to follow a malicious link. A successful attacker executes arbitrary code with root privileges on the hosting server, compromising the control panel, every site it hosts, and the underlying OS. All Plesk deployments are potentially affected, but the specific vulnerable version range is not given in the available data, so operators should consult WebPros advisory AV26-854 for fixed releases. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.
What to do: Upgrade Plesk to the fixed version specified in WebPros advisory AV26-854 as soon as it is published, and verify the installed version in the panel. Until patching, restrict access to the Plesk interface (typically TCP 8443) to trusted IPs or VPN and limit which untrusted accounts have panel/file-management access on shared servers. As a precaution, check customer-writable directories for unexpected symlinks that could reach sensitive files.
Estimated exposure
mass≈250,000+ Plesk servers (vendor-reported install base), most with network-reachable panels — WebPros/Plesk publicly cites on the order of 250,000+ servers running its panel, and the standard deployment exposes the Plesk interface over the network to tenant accounts, which bounds the potentially exposed population at several…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.