ZeroHour
Cyber Security Newspublished ()ingested Abinaya

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

AI summary · glm-5.3

CVE-2026-68488 in Plesk Backup Manager lets low-privileged subscription users exploit a symlink race during restores to gain root on Linux servers.

CVE-2026-68488 is a symlink race condition in Plesk Obsidian for Linux Backup Manager during subscription-content restore operations, allowing a user with Panel and FTP access to change ownership of files outside their subscription and escalate to full root access. Affected versions are Plesk for Linux 18.0.80.6 and earlier and 18.0.79.10 and earlier; Plesk for Windows is not affected. Patches are available in 18.0.80.7 and 18.0.79.11 or later. The flaw requires valid subscription access, so it is not unauthenticated remote code execution, but successful exploitation yields complete server compromise, especially dangerous in shared-hosting and multi-tenant deployments.

  • Symlink race in Backup Manager restore workflow enables ownership hijack
  • Affects Plesk Obsidian for Linux 18.0.80.6 and 18.0.79.10 and earlier
  • Fixed in versions 18.0.80.7 and 18.0.79.11
  • Requires authenticated Panel plus FTP access, not unauthenticated RCE
  • Particularly risky for shared hosting and multi-tenant servers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-68488
TOCTOU Symlink Race in Plesk Allows Local Privilege Escalation to Root

CVE-2026-68488 is a Time-of-check Time-of-use (TOCTOU) race condition in Plesk that causes the software to insecurely follow symbolic links (CWE-367). An attacker who already holds a low-privileged account on the server (for example, a hosting customer on a shared host) can race a privileged Plesk file operation, swapping in attacker-controlled symlinks so that the operation acts on files or directories of the attacker's choosing. By winning the race, the attacker takes ownership of arbitrary files or directories, which the vendor states leads to privilege escalation to root on the host. This means any multi-tenant or single-tenant server running Plesk where untrusted users have local access is at risk of full root compromise. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.

Do: Apply the patched Plesk release referenced in the vendor security advisory (no fixed version number is available in the data provided, so check Plesk's advisory for the exact build). In the interim, restrict or review low-privileged shell access for tenants on Plesk servers and audit cron/backup tasks that run as root, since the race likely targets such privileged file operations. Check system files and directories for unexpected ownership changes, and prioritize hosts hosting untrusted customers.

9.9
  • Plesk (server hosting/automation panel)
largetens to hundreds of thousands of Plesk-managed servers worldwide (estimated; no install-base figure in the provided data)
Full article490 words · extracted from cybersecuritynews.com · click to collapse

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers.

Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations.

The issue affects Plesk Obsidian installations running Plesk for Linux versions 18.0.80.6 and earlier, as well as 18.0.79.10 and earlier. Plesk for Windows is not affected.

According to Plesk, the vulnerability exists in the Backup Manager workflow used to restore content belonging to a customer subscription. A user with ordinary access to the Plesk Panel and FTP access to their own hosted subscription may exploit a race condition involving symbolic links (symlinks).

Symlinks are filesystem objects that point to another file or directory. In this case, an attacker may try to replace or manipulate a path during the restore process so Plesk changes ownership of a file or directory outside the attacker’s assigned subscription.

Plesk Backup Manager Flaw

Because restore operations may run with elevated privileges, a successful race could let the attacker change ownership of files that should be inaccessible.

Gaining control over a sensitive file or directory could then be leveraged to achieve complete root-level access to the underlying Linux server.

The vulnerability is particularly significant for shared-hosting environments, managed servers, and multi-tenant Plesk deployments. In such configurations, customers typically receive limited Panel and FTP permissions.

They should not be able to interact with operating system files, other customer subscriptions, or administrative resources. CVE-2026-68488 breaks that security boundary by potentially allowing a customer account to affect files outside its own hosting environment.

An attacker would need valid access to a Plesk subscription, meaning the flaw is not an unauthenticated remote code execution vulnerability. However, the impact remains severe because successful exploitation can result in full server compromise.

Plesk has released patched versions for the affected Linux product branches. Organizations using the 18.0.80 release line should update to Plesk Obsidian 18.0.80.7 or later. Those using the 18.0.79 branch should upgrade to version 18.0.79.11 or later.

Administrators should prioritize patching internet-facing and multi-tenant Plesk servers, especially systems where customers have FTP access and can trigger backup or restore-related functionality.

Hosting providers should also review Plesk user accounts, subscription permissions, and recent restore activity for unexpected ownership changes.

Security teams can look for unusual file ownership modifications outside customer web roots, unexpected symlinks within subscription directories, and suspicious activity involving Backup Manager restore operations. Reviewing privileged filesystem changes and authentication logs may help identify attempted exploitation.

Plesk credited security researchers Ali Mustafa, also known as rz1027, and abed1526 for responsibly reporting the vulnerability. The vendor advises customers to update Plesk Obsidian to the latest available build as soon as possible.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/plesk-backup-manager-flaw/