Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Execution via Symlink Resolution in Plesk Site Import and Migrator |
Wed, 26 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-08-26T21:21:41.033Z
Reserved: 2026-07-22T15:00:06.104Z
Link: CVE-2026-65647
No data.
Status : Received
Published: 2026-08-26T22:16:26.157
Modified: 2026-08-26T22:16:26.157
Link: CVE-2026-65647
No data.
OpenCVE Enrichment
Updated: 2026-08-26T23:45:03Z