Plesk - CVE-2026-87898 was discovered in Plesk's Site Import extension
Situation
A security vulnerability CVE-2026-87898 was discovered in Plesk's Site Import extension. A database name submitted during an import is not quoted as data before it is used in a command that runs with root privileges, which allows command injection.
Affected product version
Site Import extension on Plesk for Linux 1.12.1 and earlier
Impact
Arbitrary code execution as root is possible. A Plesk customer without elevated privileges can run commands as the root user on the Plesk server.
This can expose other subscriptions, databases, credentials, and the configuration of the server.
Meet Nix and Bruce @ https://twobirdsonelesbox.com
My project/stuff page @ https://serveraddict.net
Tagged:



