Vulnerability
Published 2026-09-10
Verified 2026-09-19

Plesk Backup Manager CVE-2026-68487/68488 (CVSS 9.9): authenticated customer to root on Linux

WebPros Plesk security articles (updated 10 September 2026) cover two Critical Backup Manager flaws on Plesk for Linux. CVE-2026-68487 is path traversal via an unsigned backup header that lets an authenticated customer write arbitrary root-owned files on the host (full server compromise). CVE-2026-68488 is a TOCTOU symlink race during subscription-content restore that can change ownership of directories outside the attacker’s subscription, likewise enabling root. Both carry CVSS 3.0 9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) per the HackerOne CNA records. Affected: Plesk for Linux 18.0.80.6 and earlier, and 18.0.79.10 and earlier; Plesk for Windows not affected. Fixed: 18.0.80.7 and 18.0.79.11 or later. No interim mitigation listed — update is the remediation. Multi-tenant / shared-hosting boxes with customer Panel+FTP are the highest priority. Wire: Cyber Security News (13 Sep) on 68488. Primary: Plesk KB for CVE-2026-68487; companion KB for CVE-2026-68488.

Product
WebPros Plesk Obsidian Backup Manager (Linux)
Versions
Affected: Plesk for Linux ≤18.0.80.6 and ≤18.0.79.10; fixed 18.0.80.7 / 18.0.79.11+; Windows not affected
CVSS
(CVE-2026-68487 and CVE-2026-68488, CVSS 3.0)
Exploited in Australia?
unknown
Patch to
Update Plesk Obsidian to 18.0.79.11 or 18.0.80.7 or later; hunt unexpected ownership changes outside subscription web roots and Backup Manager restore activity

Primary: Plesk KB — CVE-2026-68487 Backup Manager path traversal (10 Sep 2026) · Vendor: Plesk KB — CVE-2026-68488 symlink race (Sep 2026) · CVE: CVE-2026-68487, CVE-2026-68488 · Cyber Security News (13 Sep 2026); also NVD CVE-2026-68487/68488

vulnerabilities cloud