Volver a los avisos de seguridad

Plesk CVE-2026-65647: Link Following

Plesk is affected by CVE-2026-65647. Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. Affected versions: Migrator before 2.36.0, Site Import before 1.12.1. CVSS base score: 8.7.

Critical 8.7 CVSS
Plesk AlmaLinux 8 AlmaLinux 9 CloudLinux 8 CloudLinux 9 Debian 11 Debian 12 Ubuntu 20.04 Ubuntu 22.04

Versiones afectadas

Migrator before 2.36.0, Site Import before 1.12.1

CMD de actualización por defecto

# Update the Migrator extension to 2.36.0 and Site Import to 1.12.1

Comandos de corrección

All supported operating systems

# Update the Migrator extension to 2.36.0 and Site Import to 1.12.1
# Plesk → Extensions → Updates → apply pending updates

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense Plesk license itself is not affected — this is a vulnerability in Plesk, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-65647

Preguntas frecuentes

What is CVE-2026-65647?
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. Affected versions: Migrator before 2.36.0, Site Import before 1.12.1.
Is CVE-2026-65647 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. With a CVSS base score of 8.7, apply the update on your next maintenance window and watch the vendor advisory for changes.
How do I fix CVE-2026-65647?
Update the Migrator extension to 2.36.0 and Site Import to 1.12.1. Plesk → Extensions → Updates → apply pending updates.
Which versions are affected?
Affected: Migrator before 2.36.0, Site Import before 1.12.1. Update to the latest release.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema