Articles in this section

Vulnerability in Plesk's Backup Manager: unsigned backup header allows path traversal

kb: security kb: ai-created

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. This security vulnerability has been identified as CVE-2026-68487.

Affected product version

Product Affected versions Patched versions

Plesk for Linux

18.0.80.6 and earlier
18.0.79.10 and earlier

18.0.80.7
18.0.79.11

Plesk for Windows

Not affected

Not applicable

Impact

An authenticated customer can write arbitrary root-owned files to the host filesystem, leading to full server compromise.

Call to action

Update to Plesk Obsidian to 18.0.79.11 or 18.0.80.7 or later: How to update Plesk Obsidian to the latest build

Acknowledgements

We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.