Zurück zu den Sicherheitshinweisen

Plesk CVE-2026-65647: Link Following

Plesk is affected by CVE-2026-65647. Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. Affected versions: Migrator before 2.36.0, Site Import before 1.12.1. CVSS base score: 8.7.

Critical 8.7 CVSS
Plesk AlmaLinux 8 AlmaLinux 9 CloudLinux 8 CloudLinux 9 Debian 11 Debian 12 Ubuntu 20.04 Ubuntu 22.04

Betroffene Versionen

Migrator before 2.36.0, Site Import before 1.12.1

Standard-Update-Befehl

# Update the Migrator extension to 2.36.0 and Site Import to 1.12.1

Fix-Befehle

All supported operating systems

# Update the Migrator extension to 2.36.0 and Site Import to 1.12.1
# Plesk → Extensions → Updates → apply pending updates

Was das unter einer SharedLicense-Lizenz bedeutet

Your SharedLicense Plesk license itself is not affected — this is a vulnerability in Plesk, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-65647

Häufig gestellte Fragen

What is CVE-2026-65647?
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. Affected versions: Migrator before 2.36.0, Site Import before 1.12.1.
Is CVE-2026-65647 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. With a CVSS base score of 8.7, apply the update on your next maintenance window and watch the vendor advisory for changes.
How do I fix CVE-2026-65647?
Update the Migrator extension to 2.36.0 and Site Import to 1.12.1. Plesk → Extensions → Updates → apply pending updates.
Which versions are affected?
Affected: Migrator before 2.36.0, Site Import before 1.12.1. Update to the latest release.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen