A security vulnerability (CVE-2026-87898) was discovered in the Plesk Site Import extension on Linux servers, where improper sanitization of database names during imports could allow unauthorized command execution with root privileges, affecting version 1.12.1 and earlier. Investigation revealed that only a subset of hosts were running the vulnerable extension. Over approximately 11.7 hours, the engineering team remediated all affected environments by upgrading the extension to the patched version 1.12.2, with no further action required.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
Our team has completed the remediation work for the affected environments. No further action is required at this time.
Thank you for your patience.
We have identified that only a subset of hosts are reported with the vulnerable Site Import extension.
Our team is mitigating this vulnerability by upgrading this extension to the patched version.
Meanwhile, your time and patience will be appreciated.
We have identified a security vulnerability CVE-2026-87898 in the Plesk Site Import extension on Linux servers.
This issue involves improper sanitization of database names during imports, which could allow unauthorized command execution with root privileges.
Affected product version:
Plesk for Linux: 1.12.1 and earlier
Patched on: 1.12.2
Our engineering team is currently assessing our entire hosting fleet and determining next steps.
If you have any further questions or concerns, please contact us at support@liquidweb.com or via Live Chat.
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with