CVE-2026-65647: High severity Plesk Plesk vulnerability
Published Aug 26, 2026
·Updated
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
Affected Software
1 affected component
Plesk Plesk
Event History
Aug 26, 2026
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require unauthenticated access?
No. The issue is described as exploitable by remote authenticated users, so an attacker needs valid authenticated access to the affected Plesk environment.
2
Which Plesk functionality is associated with this issue?
The supplied reference identifies Plesk's Site Import and Migrator extensions as the affected functionality.