ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

WebPros security advisory (AV26-854)

AI summary · glm-5.3-flash

Canadian Centre for Cyber Security relayed a WebPros advisory covering Plesk vulnerabilities CVE-2026-65642 and CVE-2026-65647 with fixed versions released.

WebPros released a security advisory affecting Plesk versions prior to 18.0.79.8 and 18.0.80.4, Plesk Migrator prior to 2.36.0, and Plesk Site Import prior to 1.12.1. The listed vulnerabilities are CVE-2026-65642 in Plesk's database management interface and CVE-2026-65647 in the Site Import and Migrator extensions. The Canadian Centre for Cyber Security (AV26-854) encourages users and administrators to apply the available updates.

  • Plesk fixed in 18.0.79.8 and 18.0.80.4
  • CVE-2026-65642 affects Plesk database management interface
  • CVE-2026-65647 affects Site Import and Migrator extensions
  • Relayed by Canadian Centre for Cyber Security as AV26-854

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65642
Authenticated IDOR in WebPros Plesk exposes other customers' databases

CVE-2026-65642 is an insecure direct object reference (IDOR, CWE-639) in Plesk, the WebPros hosting control panel, affecting versions 18.0.79.7 and earlier as well as 18.0.80 through 18.0.80.3. A remote user with a valid account on the server can reference a database identifier belonging to a different customer without an ownership check, because the application fails to verify that the requested object belongs to the requesting user. This lets the attacker read and modify other customers' databases on a shared Plesk server, giving high confidentiality and integrity impact but no availability impact (CVSS 4.0: 8.6 High). Exposure is concentrated in multi-tenant hosting environments, where hosting providers and agencies run one Plesk server for many customer accounts; single-tenant deployments have little to lose from this flaw. As of now there is no public proof of concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days, so exploitation has not been observed.

Do: Upgrade Plesk to a release newer than 18.0.80.3 (consult WebPros advisory AV26-854 for the exact fixed build). Until patched, limit which subscriber accounts can manage databases, check access logs for signs of cross-customer database reads or writes, and ensure customers use least-privilege database credentials. Prioritize patching servers that host many third-party customers, since exploitation requires an authenticated account on a shared instance.

8.6<1%
  • WebPros Plesk 18.0.79.7 and earlier; 18.0.80 through 18.0.80.3
largetens of thousands of internet-exposed Plesk servers, plausibly hundreds of thousands of hosted customer accounts
CVE-2026-65647
Authenticated Root RCE via Improper Symlink Handling in Plesk

Plesk, the WebPros hosting control panel, resolves symlinks without verifying their targets before file access (CWE-59, link following), so privileged panel operations can be redirected through an attacker-controlled symlink. The flaw is triggered remotely by an authenticated low-privileged user — for example a tenant account on a shared hosting server — who gets Plesk's privileged file operations to follow a malicious link. A successful attacker executes arbitrary code with root privileges on the hosting server, compromising the control panel, every site it hosts, and the underlying OS. All Plesk deployments are potentially affected, but the specific vulnerable version range is not given in the available data, so operators should consult WebPros advisory AV26-854 for fixed releases. No public PoC, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

Do: Upgrade Plesk to the fixed version specified in WebPros advisory AV26-854 as soon as it is published, and verify the installed version in the panel. Until patching, restrict access to the Plesk interface (typically TCP 8443) to trusted IPs or VPN and limit which untrusted accounts have panel/file-management access on shared servers. As a precaution, check customer-writable directories for unexpected symlinks that could reach sensitive files.

8.7<1%
  • Plesk (WebPros) Plesk
mass≈250,000+ Plesk servers (vendor-reported install base), most with network-reachable panels
Full article

Serial number: AV26-854 Date: August 27, 2026 As of August 26, 2026, WebPros is affected by vulnerabilities in the following products: Plesk Prior to 18.0.79.8 Prior to 18.0.80.4 Plesk Migrator Prior to 2.36.0 Plesk Site Import Prior to 1.12.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerability CVE-2026-65642 in Plesk's database management interface Vulnerability CVE-2026-65647 in Plesk's Site Import and Migrator extensions

This source does not provide full text. Read it at cyber.gc.ca.