WebPros security advisory (AV26-961)
Canada's Cyber Centre urges patches for root code-execution flaws in Plesk, cPanel, and WebPros extensions.
The Canadian Centre for Cyber Security issued advisory AV26-961 on WebPros vulnerabilities affecting Plesk, its extensions, WP Toolkit, and cPanel/WHM. CVE-2026-68492 and CVE-2026-87898 allow arbitrary code execution as root through the Plesk RESTful API and Site Import extensions. CVE-2026-87899 concerns cPanel CalDAV/CardDAV, and CVE-2026-87900 concerns WP Toolkit database creation. Administrators are urged to apply updates; the advisory does not report exploitation.
- CVE-2026-68492 allows root code execution via the Plesk RESTful API extension.
- CVE-2026-87898 allows root code execution in Plesk's Site Import extension.
- CVE-2026-87899 and CVE-2026-87900 affect cPanel CalDAV/CardDAV and WP Toolkit.
- Affected Plesk 18.0 and several cPanel/WHM builds should be updated; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-684928.7—Authenticated Root Code Execution via Untrusted Search Path in Plesk RESTful APIpublished · Plesk Obsidian
- CVE-2026-878989.4—Authenticated OS Command Injection in Plesk Yields Root Code Executionpublished · Plesk (WebPros) Plesk hosting control panel
Full article142 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-961
Date: September 24, 2026
As of September 23, 2026, WebPros is affected by vulnerabilities in the following products:
- Plesk
- Versions 18.0.34 to 18.0.80.7
- Version 18.0.81.0
- Plesk extension "Plesk RESTful API"
- Versions 2.4.2 to 2.4.6
- Plesk extension "Site Import"
- Prior to or equal to 1.12.1
- WP Toolkit for cPanel
- Prior to or equal to 6.11.2-10794
- cPanel/WHM
- Prior to 11.134.0.57
- Prior to 11.136.0.41
- Prior to 11.138.0.8
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Vulnerability CVE-2026-68492: Arbitrary code execution as root in Plesk via the Plesk RESTful API extension
- Vulnerability CVE-2026-87898: Arbitrary code execution as root in Plesk's Site Import extension
- Security: CVE-2026-87899 Vulnerability in cPanel's CalDAV/CardDAV - September 22, 2026 – cPanel
- Security: CVE-2026-87900 Vulnerability in WP Toolkit Database Creation - September 22, 2026 – cPanel
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/webpros-security-advisory-av26-961