A recent vulnerability identified in Plesk Backup Manager presents a severe risk by enabling users with limited privileges to escalate their permissions and potentially gain root access on compromised Linux servers.
Details of the Vulnerability
The flaw, cataloged as CVE-2026-68488, originates from a symlink race condition during the restoration of subscription content. This issue affects installations of Plesk Obsidian on Linux, specifically versions 18.0.80.6 and earlier, and 18.0.79.10 and earlier. Notably, Plesk for Windows is exempt from this issue.
Impact on Affected Systems
The vulnerability is embedded in the Backup Manager’s workflow, primarily utilized for restoring customer subscription content. Users with standard access to the Plesk Panel and their own FTP accounts can exploit symlink race conditions, potentially redirecting file ownerships outside their designated subscriptions.
Symbolic links, or symlinks, act as pointers to other files or directories. During a restore operation, if an attacker manipulates these links, they can improperly alter file ownerships, granting access to sensitive areas of the system.
Potential Consequences and Mitigation
This vulnerability is particularly concerning in shared hosting environments, managed servers, and multi-tenant deployments. Typically, users in these settings have restricted permissions, preventing them from accessing system files or other users’ data. However, CVE-2026-68488 disrupts these security barriers, allowing potential unauthorized access.
Though an attacker requires valid access credentials to exploit this flaw, the repercussions of a successful attack could lead to full server control. Consequently, Plesk has released updates to address this issue. It is crucial for users of the 18.0.80 and 18.0.79 branches to upgrade to versions 18.0.80.7 or 18.0.79.11, respectively.
Recommendations for Administrators
Administrators are advised to prioritize updates for internet-facing and multi-tenant servers, especially where customers have FTP access. Hosting providers should reassess user accounts, subscription permissions, and recent restoration activities for any unusual changes in file ownership.
Security teams should monitor for unexpected file ownership changes, anomalous symlink behaviors within directories, and any suspicious Backup Manager activities. Scrutinizing filesystem changes and authentication logs may help detect potential exploitation attempts.
Plesk acknowledges security researchers Ali Mustafa (rz1027) and abed1526 for their responsible vulnerability disclosure. The company strongly encourages all users to apply the latest updates to secure their systems promptly.
