Full Report
WebPros security advisory (AV26-961)
Analysis Summary
# Vulnerability: Multiple Critical Flaws in WebPros Products (Plesk & cPanel)
## CVE Details
- **CVE ID:** CVE-2026-68492, CVE-2026-87898, CVE-2026-87899, CVE-2026-87900
- **CVSS Score:** Not explicitly listed in source, but characterized by "Arbitrary code execution as root" (Estimated Critical: 9.0 - 10.0)
- **CWE:** Improper Input Validation / Privilege Escalation
## Affected Systems
- **Products:**
- Plesk (with RESTful API or Site Import extensions)
- cPanel/WHM
- WP Toolkit for cPanel
- **Versions:**
- **Plesk:** 18.0.34 to 18.0.80.7 and 18.0.81.0
- **Plesk RESTful API extension:** 2.4.2 to 2.4.6
- **Plesk Site Import extension:** ≤ 1.12.1
- **WP Toolkit for cPanel:** ≤ 6.11.2-10794
- **cPanel/WHM:** Prior to 11.134.0.57, 11.136.0.41, and 11.138.0.8
- **Configurations:** Systems utilizing the RESTful API, Site Import tools, CalDAV/CardDAV services, or WP Toolkit database creation features.
## Vulnerability Description
This advisory covers multiple vulnerabilities across the WebPros ecosystem:
1. **Remote Code Execution (RCE):** Flaws in the Plesk RESTful API and Site Import extensions allow for arbitrary code execution with **root-level privileges**, the highest level of system access.
2. **Service Vulnerabilities:** A security flaw exists in cPanel's CalDAV/CardDAV implementation.
3. **Database Security:** A vulnerability in the WP Toolkit (cPanel version) occurs during the database creation process, potentially leading to unauthorized access or manipulation.
## Exploitation
- **Status:** Not explicitly stated as exploited in the wild, but categorized as high-risk due to root access potential.
- **Complexity:** Low to Medium (based on the nature of API and import extensions).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** Total (Full system access/Root).
- **Integrity:** Total (Full system access/Root).
- **Availability:** Total (Full system access/Root).
## Remediation
### Patches
Users are urged to update to the following versions or higher:
- **cPanel/WHM:** 11.134.0.57, 11.136.0.41, or 11.138.0.8.
- **Plesk:** Update extensions to versions beyond those listed in the "Affected Systems" section via the Plesk extension catalog.
- **WP Toolkit for cPanel:** Version 6.11.3 or higher.
### Workarounds
- Disable the **Plesk RESTful API** and **Site Import** extensions if they are not actively required until patches are applied.
- Limit access to CalDAV/CardDAV ports via firewall if services are not in use.
## Detection
- **Indicators of compromise:** Monitor for unauthorized root-level processes originating from the web server user, unusual API calls in Plesk logs, and unexpected database users created via WP Toolkit.
- **Detection methods:** Review system logs (`/var/log/plesk/`) and cPanel access logs for suspicious activity targeting the affected components.
## References
- **WebPros/Plesk Advisory (RCE):** hxxps[://]support[.]plesk[.]com/hc/en-us/articles/43644058632983
- **WebPros/Plesk Advisory (Site Import):** hxxps[://]support[.]plesk[.]com/hc/en-us/articles/43641151026583
- **cPanel Security (CalDAV):** hxxps[://]support[.]cpanel[.]net/hc/en-us/articles/43591715125271
- **cPanel Security (WP Toolkit):** hxxps[://]support[.]cpanel[.]net/hc/en-us/articles/43597969409943
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/webpros-security-advisory-av26-961