Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-87898: Plesk Site Import extension lets users run code as admin
CVE-2026-87898 · published 16 days ago
Summary
The Site Import add‑on for Plesk can be used by someone who has an account to run any commands on the server, giving them the same power as the system’s administrator. This could let an attacker change settings, access data, or install unwanted software. Apply the latest update from the vendor and restrict who can log in to the control panel.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | plesk extension "site import" | <= 1.12.1 |
Original advisory text
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-78OS Command Injection
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta