Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-87898: Plesk Site Import extension lets users run code as admin

CVE-2026-87898 · published 16 days ago
Summary

The Site Import add‑on for Plesk can be used by someone who has an account to run any commands on the server, giving them the same power as the system’s administrator. This could let an attacker change settings, access data, or install unwanted software. Apply the latest update from the vendor and restrict who can log in to the control panel.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
webpros plesk extension "site import" <= 1.12.1
Original advisory text
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-87898 · MITRE
Track software like this
Free during beta