ZeroHour

CVE-2026-68488

large1

TOCTOU Symlink Race in Plesk Allows Local Privilege Escalation to Root

CVSS 3.0
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-68488 is a Time-of-check Time-of-use (TOCTOU) race condition in Plesk that causes the software to insecurely follow symbolic links (CWE-367). An attacker who already holds a low-privileged account on the server (for example, a hosting customer on a shared host) can race a privileged Plesk file operation, swapping in attacker-controlled symlinks so that the operation acts on files or directories of the attacker's choosing. By winning the race, the attacker takes ownership of arbitrary files or directories, which the vendor states leads to privilege escalation to root on the host. This means any multi-tenant or single-tenant server running Plesk where untrusted users have local access is at risk of full root compromise. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.

What to do: Apply the patched Plesk release referenced in the vendor security advisory (no fixed version number is available in the data provided, so check Plesk's advisory for the exact build). In the interim, restrict or review low-privileged shell access for tenants on Plesk servers and audit cron/backup tasks that run as root, since the race likely targets such privileged file operations. Check system files and directories for unexpected ownership changes, and prioritize hosts hosting untrusted customers.

Affected
Plesk (server hosting/automation panel)
Estimated exposure
largetens to hundreds of thousands of Plesk-managed servers worldwide (estimated; no install-base figure in the provided data) — Plesk is one of the most widely deployed commercial hosting control panels and is standard among shared-hosting providers, and public internet scans have historically shown tens of thousands of exposed Plesk panels, so the plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

Weakness
CWE-367
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

CVE-2026-68488 in Plesk Backup Manager lets low-privileged subscription users exploit a symlink race during restores to gain root on Linux servers.

CVE-2026-68488 is a symlink race condition in Plesk Obsidian for Linux Backup Manager during subscription-content restore operations, allowing a user with Panel and FTP access to change ownership of files outside their subscription and escalate to full root access. Affected versions are Plesk for Linux 18.0.80.6 and earlier and 18.0.79.10 and earlier; Plesk for Windows is not affected. Patches are available in 18.0.80.7 and 18.0.79.11 or later. The flaw requires valid subscription access, so it is not unauthenticated remote code execution, but successful exploitation yields complete server compromise, especially dangerous in shared-hosting and multi-tenant deployments.