DIRAS TAKE
Patch urgently: public exploit code exists and vendor updates are available (2.36.0 and 1.12.1), so prioritize upgrading exposed systems immediately.
What is CVE-2026-65647?
Authenticated users can exploit a symlink resolution flaw in Plesk Migrator to gain root-level code execution; tracked as CVE-2026-65647. The issue affects Plesk Migrator 2.x before 2.36.0 and Plesk Site Import 1.x before 1.12.1. An attacker requires an account on the target Plesk service (no user interaction is required) and network access to the service. The vulnerability stems from improper symlink handling before file access which can be abused to escalate privileges and execute arbitrary commands as root on vulnerable installations. The weakness is classified as CWE-59 (Link Following).
Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Which versions of WebPros Plesk Migrator are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Plesk Migrator 2.x | before 2.36.0 | 2.36.0 |
| Plesk Site Import 1.x | before 1.12.1 | 1.12.1 |
Is CVE-2026-65647 being exploited?
Public exploit code is available.
How to fix CVE-2026-65647
- Upgrade Plesk Migrator 2.x to 2.36.0 or later and Plesk Site Import 1.x to 1.12.1 or later.
- Restrict access to the Plesk Migrator/Site Import interfaces to trusted networks while you patch.
- Follow vendor guidance and apply any additional configuration hardening recommended by WebPros.
- Monitor system and application logs for suspicious file operations and unexpected privilege escalations.
Frequently asked questions
Is CVE-2026-65647 being actively exploited?
Public exploit code is available for CVE-2026-65647, indicating a higher risk of active exploitation.
Which Plesk Migrator versions are affected by CVE-2026-65647?
Plesk Migrator 2.x versions before 2.36.0 and Plesk Site Import 1.x versions before 1.12.1 are affected by CVE-2026-65647.
Is there a patch for CVE-2026-65647?
Yes. WebPros released fixes: update Plesk Migrator 2.x to 2.36.0 and Plesk Site Import 1.x to 1.12.1.
Does CVE-2026-65647 require authentication?
Yes. CVE-2026-65647 requires an authenticated account on the Plesk product to exploit the symlink flaw.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65647
- cve.org/CVERecord?id=CVE-2026-65647
- support.plesk.com/hc/en-us/articles/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions
- All WebPros CVEs on CVE Radar
- CVEs published in September 2026