ZeroHour
Product

Plesk Site Import

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

WebPros security advisory (AV26-854)

Canadian Centre for Cyber Security relayed a WebPros advisory covering Plesk vulnerabilities CVE-2026-65642 and CVE-2026-65647 with fixed versions released.

WebPros released a security advisory affecting Plesk versions prior to 18.0.79.8 and 18.0.80.4, Plesk Migrator prior to 2.36.0, and Plesk Site Import prior to 1.12.1. The listed vulnerabilities are CVE-2026-65642 in Plesk's database management interface and CVE-2026-65647 in the Site Import and Migrator extensions. The Canadian Centre for Cyber Security (AV26-854) encourages users and administrators to apply the available updates.

Related CVEs

  • Authenticated Root RCE via Improper Symlink Handling in Plesk
    Plesk, the WebPros hosting control panel, resolves symlinks without verifying their targets before file access (CWE-59, link following), so privileged panel operations can be redirected through an attacker-controlled symlink. The flaw is triggered remotely by an authenticated low-privileged user — for example a tenant account on a shared hosting server — who gets Plesk's privileged file operations to follow a malicious link. A successful attacker executes arbitrary code with root privileges on the hosting server, compromising the control panel, every site it hosts, and the underlying OS. All Plesk deployments are potentially affected, but the specific vulnerable version range is not given in the available data, so operators should consult WebPros advisory AV26-854 for fixed releases. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.
    · Plesk (WebPros) Pleskmass
  • Authenticated IDOR in WebPros Plesk exposes other customers' databases
    CVE-2026-65642 is an insecure direct object reference (IDOR, CWE-639) in Plesk, the WebPros hosting control panel, affecting versions 18.0.79.7 and earlier as well as 18.0.80 through 18.0.80.3. A remote user with a valid account on the server can reference a database identifier belonging to a different customer without an ownership check, because the application fails to verify that the requested object belongs to the requesting user. This lets the attacker read and modify other customers' databases on a shared Plesk server, giving high confidentiality and integrity impact but no availability impact (CVSS 4.0: 8.6 High). Exposure is concentrated in multi-tenant hosting environments, where hosting providers and agencies run one Plesk server for many customer accounts; single-tenant deployments have little to lose from this flaw. As of now there is no public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days, so exploitation has not been observed.
    · WebPros Plesk 18.0.79.7 and earlier; 18.0.80 through 18.0.80.3large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.