CVE-2026-68487
massPath Traversal in Plesk Backup Manager Allows Arbitrary File Write as Root
CVE-2026-68487 is a path traversal flaw (CWE-36) in the Backup Manager component of the Plesk hosting control panel, where insufficient path handling allows a file write to escape the intended directory. It is triggered over the network by a low-privileged, authenticated customer account (CVSS PR:L), with no user interaction or special conditions required (AV:N/AC:L/UI:N). Because the attack changes scope (S:C), the write occurs with root privileges on the host, giving the attacker arbitrary file write as root and high potential impact to confidentiality, integrity, and availability — typically a route to full server compromise. Any Plesk deployment that exposes Backup Manager functionality to customer-level users, which is common on shared and reseller hosting servers, is affected. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation is known.
What to do: Upgrade Plesk to the patched build as soon as the vendor advisory identifies it (no fixed version is given in this data), and until then restrict Backup Manager access so customer/subscription-level users cannot invoke it. Also audit affected hosts for unexpected root-owned file changes (e.g., cron entries, SSH authorized_keys, or system configuration files) as indicators of exploitation, and monitor Plesk/HackerOne disclosures for updates.
| Plesk (WebPros) Plesk Backup Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
- Weakness
- CWE-36
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.