Liquid Web Status · History · Incident #141670
RESOLVEDSecurity vulnerability CVE-2026-87898 on Plesk's Site Import extension
Minor · Started Sep 26, 2026 · 11:10 AM
Liquid Web Status · History · Incident #141670
RESOLVEDMinor · Started Sep 26, 2026 · 11:10 AM
Duration
11h 40m
Severity
Minor
Detection lead
—
User reports
—
Summary
Our team has completed the remediation work for the affected environments. No further action is required at this time. Thank you for your patience.
Started
Sep 26, 2026 · 11:10 AM
Resolved
Sep 26, 2026 · 10:50 PM
Duration
11h 40m
Severity
None
Event timeline
Investigating
Sep 26 · 11:10 AM Liquid WebWe have identified a security vulnerability CVE-2026-87898 in the Plesk Site Import extension on Linux servers. This issue involves improper sanitization of database names during imports, which could allow unauthorized command execution with root privileges. Affected product version: Plesk for Linux: 1.12.1 and earlier Patched on: 1.12.2 Our engineering team is currently assessing our entire hosting fleet and determining next steps. If you have any further questions or concerns, please contact us at support@liquidweb.com or via Live Chat.
Identified
Sep 26 · 12:10 PM Liquid WebWe have identified that only a subset of hosts are reported with the vulnerable Site Import extension. Our team is mitigating this vulnerability by upgrading this extension to the patched version. Meanwhile, your time and patience will be appreciated.
Resolved
Sep 26 · 10:50 PM Liquid WebOur team has completed the remediation work for the affected environments. No further action is required at this time. Thank you for your patience.
Pattern
Add it as a dependency monitor. The Free plan includes one.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026. Pulsetic® is a registered trademark.