Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros plesk Migrator Webpros plesk Site Import |
|
| Vendors & Products |
Webpros
Webpros plesk Migrator Webpros plesk Site Import |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Execution via Symlink Resolution in Plesk Site Import and Migrator |
Wed, 26 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-08-26T21:21:41.033Z
Updated: 2026-08-27T17:59:51.351Z
Reserved: 2026-07-22T15:00:06.104Z
Link: CVE-2026-65647
Updated: 2026-08-27T17:59:46.787Z
Status : Awaiting Analysis
Published: 2026-08-26T22:16:26.157
Modified: 2026-09-03T17:02:54.670
Link: CVE-2026-65647
No data.