kb: security
kb: ai-created
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. This security vulnerability has been identified as CVE-2026-68487.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
Plesk for Linux |
18.0.80.6 and earlier |
18.0.80.7 |
Plesk for Windows |
Not affected |
Not applicable |
Impact
An authenticated customer can write arbitrary root-owned files to the host filesystem, leading to full server compromise.
Call to action
Update to Plesk Obsidian to 18.0.79.11 or 18.0.80.7 or later: How to update Plesk Obsidian to the latest build
Acknowledgements
We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.
Comments
Please sign in to leave a comment.