VYPR
patchPublished Sep 13, 2026· 1 source

Plesk Backup Manager Flaw Grants Root Access via Symlink Race Condition

A critical vulnerability in Plesk Backup Manager allows low-privileged users to escalate to root access on Linux servers through a symlink race condition.

A newly disclosed vulnerability, tracked as CVE-2026-68488, in Plesk's Backup Manager feature could allow ordinary users to escalate their privileges to full root access on affected Linux servers. The flaw is a symlink race condition that occurs during subscription content restore operations.

The vulnerability specifically impacts Plesk Obsidian versions 18.0.80.6 and earlier, and 18.0.79.10 and earlier, on Linux-based systems. Plesk for Windows is not affected by this issue.

The exploit relies on a race condition involving symbolic links (symlinks) during the restore process. A user with standard Panel and FTP access to their own hosted subscription can manipulate paths during a restore operation. Because restore operations can run with elevated privileges, a successful manipulation could trick the Plesk Backup Manager into changing the ownership of files or directories outside the attacker's assigned subscription.

This allows an attacker to gain control over sensitive files or directories that should be inaccessible, potentially leading to complete root-level access to the underlying Linux server. This is particularly concerning in shared-hosting environments and multi-tenant Plesk deployments where customer accounts are intentionally restricted from interacting with operating system files or other customer subscriptions.

While exploitation requires valid access to a Plesk subscription, meaning it is not an unauthenticated remote code execution vulnerability, the potential impact remains severe, enabling full server compromise. Hosting providers and administrators are urged to take immediate action.

Plesk has addressed the vulnerability by releasing patched versions. Customers using the 18.0.80 release line should update to Plesk Obsidian 18.0.80.7 or later. Those on the 18.0.79 branch need to upgrade to version 18.0.79.11 or later.

Administrators should prioritize patching internet-facing and multi-tenant Plesk servers, especially those where customers have FTP access and can trigger backup or restore functions. Security teams should monitor for unusual file ownership modifications outside customer web roots, suspicious symlinks within subscription directories, and unexpected activity related to Backup Manager restore operations.

The vulnerability was responsibly reported by security researchers Ali Mustafa (rz1027) and abed1526. Plesk strongly advises all customers to update their Plesk Obsidian installations to the latest available build as soon as possible to mitigate the risk.

Synthesized by Vypr AI