Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
Brief
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers.
Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations.
The issue affects Plesk Obsidian installations running Plesk for Linux versions 18.
- 80. 6 and earlier, as well as 18.
- 79. 10 and earlier. Plesk for Windows is not affected.
According to Plesk, the vulnerability exists in the Backup Manager workflow used to restore content belonging to a customer subscription. A user with ordinary access to the Plesk Panel and FTP access to their own hosted subscription may exploit a race condition involving symbolic links (symlinks).
Symlinks are filesystem objects that point to another file or directory.
