AI analysis
CVE-2026-68488 is a Time-of-check Time-of-use (TOCTOU) race condition in Plesk that causes the software to insecurely follow symbolic links (CWE-367). An attacker who already holds a low-privileged account on the server (for example, a hosting customer on a shared host) can race a privileged Plesk file operation, swapping in attacker-controlled symlinks so that the operation acts on files or directories of the attacker's choosing. By winning the race, the attacker takes ownership of arbitrary files or directories, which the vendor states leads to privilege escalation to root on the host. This means any multi-tenant or single-tenant server running Plesk where untrusted users have local access is at risk of full root compromise. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.
What to do: Apply the patched Plesk release referenced in the vendor security advisory (no fixed version number is available in the data provided, so check Plesk's advisory for the exact build). In the interim, restrict or review low-privileged shell access for tenants on Plesk servers and audit cron/backup tasks that run as root, since the race likely targets such privileged file operations. Check system files and directories for unexpected ownership changes, and prioritize hosts hosting untrusted customers.
Affected
| Plesk (server hosting/automation panel) | — |
Estimated exposure
largetens to hundreds of thousands of Plesk-managed servers worldwide (estimated; no install-base figure in the provided data) — Plesk is one of the most widely deployed commercial hosting control panels and is standard among shared-hosting providers, and public internet scans have historically shown tens of thousands of exposed Plesk panels, so the plausibly…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.