Full Report
WebPros security advisory (AV26-854)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in WebPros Plesk and Extensions
## CVE Details
*Note: Based on the provided advisory dates (2026), these represent hypothetical or future-dated security scenarios provided in the text.*
**Item 1:**
- **CVE ID:** CVE-2026-65642
- **CVSS Score:** Not explicitly listed in text (Typically High for Database Management flaws)
- **CWE:** Not specified (Likely related to Improper Input Validation or Broken Access Control)
**Item 2:**
- **CVE ID:** CVE-2026-65647
- **CVSS Score:** Not explicitly listed in text
- **CWE:** Not specified (Likely related to Insecure File Handling or Server-Side Request Forgery given the "Import/Migrator" context)
## Affected Systems
- **Products:**
- Plesk (Database Management Interface)
- Plesk Migrator Extension
- Plesk Site Import Extension
- **Versions:**
- Plesk versions prior to 18.0.79.8
- Plesk versions prior to 18.0.80.4
- Plesk Migrator prior to 2.36.0
- Plesk Site Import prior to 1.12.1
- **Configurations:** Systems utilizing the Database Management interface and migration/import extensions.
## Vulnerability Description
- **CVE-2026-65642:** A security flaw resides in the Plesk database management interface. While specific technical mechanics (e.g., SQLi or XSS) are not detailed in the summary, flaws in this component typically allow for unauthorized data manipulation or administrative access to hosted databases.
- **CVE-2026-65647:** A vulnerability affecting the Site Import and Migrator extensions. These extensions handle data transfers between servers; flaws here often involve improper validation of source data or unauthorized file system access during the migration process.
## Exploitation
- **Status:** Not specified (Assumed disclosure/patch release phase)
- **Complexity:** Not specified
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential access to database contents and site files)
- **Integrity:** High (Potential modification of database records or site configurations)
- **Availability:** Medium (Potential service disruption during exploitation)
## Remediation
### Patches
Update to the following versions or higher:
- **Plesk:** 18.0.79.8 or 18.0.80.4
- **Plesk Migrator:** 2.36.0
- **Plesk Site Import:** 1.12.1
### Workarounds
- Limit access to the Plesk administrative interface to trusted IP addresses only.
- Disable the Site Import and Migrator extensions if they are not actively in use.
## Detection
- Monitor web server logs for unusual activity directed at the database management path.
- Audit extension versions via the Plesk "Extensions" menu to ensure all components meet the minimum secure version requirements.
## References
- WebPros/Plesk Advisory (CVE-2026-65642): hxxps[://]support[.]plesk[.]com/hc/en-us/articles/42844242102679
- WebPros/Plesk Advisory (CVE-2026-65647): hxxps[://]support[.]plesk[.]com/hc/en-us/articles/42871001389207
- Cyber Centre Alert: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/webpros-security-advisory-av26-854