• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65647: authenticated symlink vulnerability in WebPros Plesk Migrator

Authenticated users can exploit a symlink resolution flaw in Plesk Migrator to gain root-level code execution; tracked as CVE-2026-65647. The issue affects Plesk Migrator 2.x before 2.36.0 and Plesk Site Import 1.x before 1.12.1. An attacker requires an account on the target Plesk service (no user interaction is required) and network access to the service. The vulnerability stems from improper symlink handling before file access which can be abused to escalate privileges and execute arbitrary commands as root on vulnerable installations.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 4.0
8.7HIGH
EPSS
0.00743
CWE
CWE-59
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Patch urgently: public exploit code exists and vendor updates are available (2.36.0 and 1.12.1), so prioritize upgrading exposed systems immediately.

What is CVE-2026-65647?

Authenticated users can exploit a symlink resolution flaw in Plesk Migrator to gain root-level code execution; tracked as CVE-2026-65647. The issue affects Plesk Migrator 2.x before 2.36.0 and Plesk Site Import 1.x before 1.12.1. An attacker requires an account on the target Plesk service (no user interaction is required) and network access to the service. The vulnerability stems from improper symlink handling before file access which can be abused to escalate privileges and execute arbitrary commands as root on vulnerable installations. The weakness is classified as CWE-59 (Link Following).

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of WebPros Plesk Migrator are affected?

BRANCHAFFECTEDFIXED
Plesk Migrator 2.xbefore 2.36.02.36.0
Plesk Site Import 1.xbefore 1.12.11.12.1

Is CVE-2026-65647 being exploited?

Public exploit code is available.

How to fix CVE-2026-65647

  1. Upgrade Plesk Migrator 2.x to 2.36.0 or later and Plesk Site Import 1.x to 1.12.1 or later.
  2. Restrict access to the Plesk Migrator/Site Import interfaces to trusted networks while you patch.
  3. Follow vendor guidance and apply any additional configuration hardening recommended by WebPros.
  4. Monitor system and application logs for suspicious file operations and unexpected privilege escalations.

Frequently asked questions

Is CVE-2026-65647 being actively exploited?

Public exploit code is available for CVE-2026-65647, indicating a higher risk of active exploitation.

Which Plesk Migrator versions are affected by CVE-2026-65647?

Plesk Migrator 2.x versions before 2.36.0 and Plesk Site Import 1.x versions before 1.12.1 are affected by CVE-2026-65647.

Is there a patch for CVE-2026-65647?

Yes. WebPros released fixes: update Plesk Migrator 2.x to 2.36.0 and Plesk Site Import 1.x to 1.12.1.

Does CVE-2026-65647 require authentication?

Yes. CVE-2026-65647 requires an authenticated account on the Plesk product to exploit the symlink flaw.

References