ZeroHour

CVE-2026-68487

mass

Path Traversal in Plesk Backup Manager Allows Arbitrary File Write as Root

CVSS 3.0
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-68487 is a path traversal flaw (CWE-36) in the Backup Manager component of the Plesk hosting control panel, where insufficient path handling allows a file write to escape the intended directory. It is triggered over the network by a low-privileged, authenticated customer account (CVSS PR:L), with no user interaction or special conditions required (AV:N/AC:L/UI:N). Because the attack changes scope (S:C), the write occurs with root privileges on the host, giving the attacker arbitrary file write as root and high potential impact to confidentiality, integrity, and availability — typically a route to full server compromise. Any Plesk deployment that exposes Backup Manager functionality to customer-level users, which is common on shared and reseller hosting servers, is affected. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation is known.

What to do: Upgrade Plesk to the patched build as soon as the vendor advisory identifies it (no fixed version is given in this data), and until then restrict Backup Manager access so customer/subscription-level users cannot invoke it. Also audit affected hosts for unexpected root-owned file changes (e.g., cron entries, SSH authorized_keys, or system configuration files) as indicators of exploitation, and monitor Plesk/HackerOne disclosures for updates.

Affected
Plesk (WebPros) Plesk Backup Manager
Estimated exposure
mass≈100,000+ Plesk servers, potentially millions of hosted customers (Plesk's install base is widely reported in the hundreds of thousands of hosting servers) — Plesk is one of the most widely deployed commercial hosting control panels with a long-reported installed base in the hundreds of thousands of servers, and because exploitation requires only a customer-level login, effectively all…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Weakness
CWE-36
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.