A security vulnerability was discovered in Plesk's Backup Manager that allows a symlink race condition during subscription content restore to change the ownership of a file or directory outside the customer's own subscription. This security vulnerability has been identified as CVE-2026-68488.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
Plesk for Linux |
18.0.80.6 and earlier |
18.0.80.7 |
Plesk for Windows |
Not affected |
Not applicable |
Impact
Exploiting this vulnerability could allow a customer with ordinary Panel and FTP access to their own subscription to gain ownership of a file or directory they do not own, ultimately leading to full root access to the server.
Call to action
Update to Plesk Obsidian to 18.0.79.11 or 18.0.80.7 or later: How to update Plesk Obsidian to the latest build
Acknowledgements
We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.
Comments
Please sign in to leave a comment.