Executive brief
Plesk, a hosting control panel used to manage web servers and customer accounts, contains a vulnerability in its symlink handling that allows authenticated attackers to execute arbitrary code with root privileges. This could enable an attacker with valid credentials to completely compromise the hosting server and access all customer data and websites hosted on it.
Technical details
This vulnerability exists in Plesk's Site Import and Migrator extensions and involves improper symlink resolution before file access (a classic TOCTOU or symlink-following flaw). The vulnerability allows remote authenticated users to execute arbitrary code as the root user. The attack requires valid authentication credentials to trigger. If exploited, an attacker gains full root-level control of the Plesk server.
Affected products
- Plesk Plesk <UNKNOWN>
Timeline
- 2026-08-26: disclosed