Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Liquid Web

Security vulnerability CVE-2026-87898 on Plesk's Site Import extension

Resolved Minor
September 26, 2026 - Started 1 day ago - Lasted about 12 hours
Official incident page

Incident Report

Summary AI Generated

A security vulnerability (CVE-2026-87898) was discovered in the Plesk Site Import extension on Linux servers, where improper sanitization of database names during imports could allow unauthorized command execution with root privileges, affecting version 1.12.1 and earlier. Investigation revealed that only a subset of hosts were running the vulnerable extension. Over approximately 11.7 hours, the engineering team remediated all affected environments by upgrading the extension to the patched version 1.12.2, with no further action required.

We have identified a security vulnerability CVE-2026-87898 in the Plesk Site Import extension on Linux servers. This issue involves improper sanitization of database names during imports, which could allow unauthorized command execution with root privileges. Affected product version: Plesk for Linux: 1.12.1 and earlier Patched on: 1.12.2 Our engineering team is currently assessing our entire hosting fleet and determining next steps. If you have any further questions or concerns, please contact us at support@liquidweb.com or via Live Chat.
Components affected
Liquid Web Plesk

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 1 day ago - at 09/27/2026 02:50AM

Our team has completed the remediation work for the affected environments. No further action is required at this time.

Thank you for your patience.

IDENTIFIED 1 day ago - at 09/26/2026 04:10PM

We have identified that only a subset of hosts are reported with the vulnerable Site Import extension.
Our team is mitigating this vulnerability by upgrading this extension to the patched version.

Meanwhile, your time and patience will be appreciated.

INVESTIGATING 1 day ago - at 09/26/2026 03:10PM

We have identified a security vulnerability CVE-2026-87898 in the Plesk Site Import extension on Linux servers.
This issue involves improper sanitization of database names during imports, which could allow unauthorized command execution with root privileges.

Affected product version:
Plesk for Linux: 1.12.1 and earlier
Patched on: 1.12.2
Our engineering team is currently assessing our entire hosting fleet and determining next steps.

If you have any further questions or concerns, please contact us at support@liquidweb.com or via Live Chat.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook