Plesk Backup Manager Critical Flaw Lets Low-Privileged Users Gain Root Access
Key Takeaways A critical privilege escalation vulnerability (CVE-2026-68488) has been discovered in Plesk Backup Manager for Linux. The flaw allows low-privileged users to gain root access on...
Key Takeaways
- A critical privilege escalation vulnerability (CVE-2026-68488) has been discovered in Plesk Backup Manager for Linux.
- The flaw allows low-privileged users to gain root access on affected Plesk Obsidian for Linux servers.
- Plesk for Windows is not affected.
- The vulnerability is particularly dangerous in shared-hosting and multi-tenant environments.
- Patches are available, and immediate updates are strongly recommended.
A significant security vulnerability in Plesk Backup Manager could enable low-privileged users to escalate their permissions and achieve full root access on vulnerable Linux servers. This critical flaw, identified as CVE-2026-68488, primarily affects Plesk Obsidian installations.
Table Of Content
The core of the vulnerability lies in a symlink race condition that occurs during the process of restoring subscription content. This issue impacts Plesk for Linux versions 18.0.80.6 and earlier, as well as versions 18.0.79.10 and earlier. Importantly, Plesk for Windows installations are not susceptible to this specific exploit.
According to Plesk has released an advisory explaining that the vulnerability manifests within the Backup Manager’s workflow for restoring customer subscription data. An attacker, possessing standard access to the Plesk Panel and FTP access to their own hosted subscription, can exploit a race condition involving symbolic links (symlinks).
Symlinks are essential filesystem objects that act as pointers to other files or directories. In this attack scenario, a malicious actor could attempt to manipulate or replace a path during the restoration process. This manipulation could trick Plesk into changing the ownership of a file or directory located outside the attacker’s authorized subscription space.
Exploiting the Race Condition
Since restore operations often execute with elevated privileges, a successful race condition could allow an attacker to alter the ownership of files that should otherwise be inaccessible to them. Gaining control over such sensitive files or directories could then be leveraged to obtain complete root-level access to the underlying Linux server.
This vulnerability carries substantial risk, especially for shared-hosting providers, managed server environments, and any multi-tenant Plesk deployments. In these setups, customers are typically granted limited Panel and FTP permissions, designed to prevent them from interacting with operating system files, other customer subscriptions, or administrative resources. CVE-2026-68488 circumvents this security boundary, potentially allowing a customer account to impact files outside its designated hosting environment.
While an attacker requires valid access to a Plesk subscription, meaning this is not an unauthenticated remote code execution vulnerability, the potential impact remains severe. Successful exploitation can lead to a full compromise of the server.
Plesk has promptly released patched versions for the affected Linux product branches. Organizations utilizing the 18.0.80 release line should update to Plesk Obsidian 18.0.80.7 or a newer version. Similarly, those on the 18.0.79 branch must upgrade to version 18.0.79.11 or later.
Security researchers Ali Mustafa (rz1027) and abed1526 were credited by Plesk for their responsible disclosure of this vulnerability. The vendor urges all customers to update their Plesk Obsidian installations to the latest available build without delay.
What You Should Do
- Update Immediately: Prioritize updating Plesk Obsidian for Linux to version 18.0.80.7 (for the 18.0.80 branch) or 18.0.79.11 (for the 18.0.79 branch) or newer.
- Prioritize Critical Systems: Focus patching efforts on internet-facing and multi-tenant Plesk servers, especially those where customers have FTP access and can initiate backup or restore functions.
- Review User Accounts and Permissions: Conduct an audit of Plesk user accounts and subscription permissions, particularly in shared-hosting environments.
- Monitor Restore Activity: Scrutinize recent restore activities for any unexpected ownership changes.
- Look for Anomalies: Investigate unusual file ownership modifications outside customer web roots, unexpected symlinks within subscription directories, and suspicious Backup Manager restore operations.
- Examine Logs: Review privileged filesystem changes and authentication logs for any signs of attempted exploitation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.