CVE-2026-65647

Summary

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Affected Software

VendorProductVersion RangeStatus
WebProsPlesk Migrator0 < 2.36.0affected
WebProsPlesk Site Import0 < 1.12.1affected

Weaknesses

  • CWE-59: CWE-59 Improper Link Resolution Before File Access ('Link Following')

References