Articles in this section

Vulnerability in Plesk's Backup Manager: symlink race during restore allows root privilege escalation

kb: security kb: ai-created

A security vulnerability was discovered in Plesk's Backup Manager that allows a symlink race condition during subscription content restore to change the ownership of a file or directory outside the customer's own subscription. This security vulnerability has been identified as CVE-2026-68488.

Affected product version

Product Affected versions Patched versions

Plesk for Linux

18.0.80.6 and earlier
18.0.79.10 and earlier

18.0.80.7
18.0.79.11

Plesk for Windows

Not affected

Not applicable

Impact

Exploiting this vulnerability could allow a customer with ordinary Panel and FTP access to their own subscription to gain ownership of a file or directory they do not own, ultimately leading to full root access to the server.

Call to action

Update to Plesk Obsidian to 18.0.79.11 or 18.0.80.7 or later: How to update Plesk Obsidian to the latest build

Acknowledgements

We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.