ZeroHour

CVE-2026-65647

mass

Authenticated Root RCE via Improper Symlink Handling in Plesk

CVSS 4.0
8.7 high
EPSS
<1%p41
Published
()
Modified
AI analysis

Plesk, the WebPros hosting control panel, resolves symlinks without verifying their targets before file access (CWE-59, link following), so privileged panel operations can be redirected through an attacker-controlled symlink. The flaw is triggered remotely by an authenticated low-privileged user — for example a tenant account on a shared hosting server — who gets Plesk's privileged file operations to follow a malicious link. A successful attacker executes arbitrary code with root privileges on the hosting server, compromising the control panel, every site it hosts, and the underlying OS. All Plesk deployments are potentially affected, but the specific vulnerable version range is not given in the available data, so operators should consult WebPros advisory AV26-854 for fixed releases. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

What to do: Upgrade Plesk to the fixed version specified in WebPros advisory AV26-854 as soon as it is published, and verify the installed version in the panel. Until patching, restrict access to the Plesk interface (typically TCP 8443) to trusted IPs or VPN and limit which untrusted accounts have panel/file-management access on shared servers. As a precaution, check customer-writable directories for unexpected symlinks that could reach sensitive files.

Affected
Plesk (WebPros) Plesk
Estimated exposure
mass≈250,000+ Plesk servers (vendor-reported install base), most with network-reachable panels — WebPros/Plesk publicly cites on the order of 250,000+ servers running its panel, and the standard deployment exposes the Plesk interface over the network to tenant accounts, which bounds the potentially exposed population at several…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Weakness
CWE-59
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

WebPros security advisory (AV26-854)

Canadian Centre for Cyber Security relayed a WebPros advisory covering Plesk vulnerabilities CVE-2026-65642 and CVE-2026-65647 with fixed versions released.

WebPros released a security advisory affecting Plesk versions prior to 18.0.79.8 and 18.0.80.4, Plesk Migrator prior to 2.36.0, and Plesk Site Import prior to 1.12.1. The listed vulnerabilities are CVE-2026-65642 in Plesk's database management interface and CVE-2026-65647 in the Site Import and Migrator extensions. The Canadian Centre for Cyber Security (AV26-854) encourages users and administrators to apply the available updates.