CVE-2026-87898

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-23: 109-23
Referenced assets2 URLs
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 Plesk'te iki kritik güvenlik açığı duyuruldu: • CVE-2026-87898: Site Import extension'daki command injection açığı, düşük yetkili bir kullanıcının root olarak keyfi kod çalıştırmasına izin veriyor. CVSS: 9.4 • CVE-2026-68492: Plesk RESTful API extension'daki açık, kimliği doğrulanmış uzak kullanıcıların root olarak keyfi kod çalıştırmasına olanak sağlıyor. CVSS: 8.7 Her iki açık da Plesk for Linux'u etkiliyor. Güncel sürümlere mutlaka güncelleyin! Duyurular: https://support.plesk.com/hc/en-us/articles/43644058632983-Vulnerability-CVE-2026-68492-Arbitrary-code-execution-as-root-in-Plesk-via-the-Plesk-RESTful-API-extension https://support.plesk.com/hc/en-us/articles/43641151026583-Vulnerability-CVE-2026-87898-Arbitrary-code-execution-as-root-in-Plesk-s-Site-Import-extension

    00011153
    2.4K followersView on X

Explore more