A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers.
Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations.
The issue affects Plesk Obsidian installations running Plesk for Linux versions 18.0.80.6 and earlier, as well as 18.0.79.10 and earlier. Plesk for Windows is not affected.
According to Plesk, the vulnerability exists in the Backup Manager workflow used to restore content belonging to a customer subscription. A user with ordinary access to the Plesk Panel and FTP access to their own hosted subscription may exploit a race condition involving symbolic links (symlinks).
Symlinks are filesystem objects that point to another file or directory. In this case, an attacker may try to replace or manipulate a path during the restore process so Plesk changes ownership of a file or directory outside the attacker’s assigned subscription.
Plesk Backup Manager Flaw
Because restore operations may run with elevated privileges, a successful race could let the attacker change ownership of files that should be inaccessible.
Gaining control over a sensitive file or directory could then be leveraged to achieve complete root-level access to the underlying Linux server.
The vulnerability is particularly significant for shared-hosting environments, managed servers, and multi-tenant Plesk deployments. In such configurations, customers typically receive limited Panel and FTP permissions.
They should not be able to interact with operating system files, other customer subscriptions, or administrative resources. CVE-2026-68488 breaks that security boundary by potentially allowing a customer account to affect files outside its own hosting environment.
An attacker would need valid access to a Plesk subscription, meaning the flaw is not an unauthenticated remote code execution vulnerability. However, the impact remains severe because successful exploitation can result in full server compromise.
Plesk has released patched versions for the affected Linux product branches. Organizations using the 18.0.80 release line should update to Plesk Obsidian 18.0.80.7 or later. Those using the 18.0.79 branch should upgrade to version 18.0.79.11 or later.
Administrators should prioritize patching internet-facing and multi-tenant Plesk servers, especially systems where customers have FTP access and can trigger backup or restore-related functionality.
Hosting providers should also review Plesk user accounts, subscription permissions, and recent restore activity for unexpected ownership changes.
Security teams can look for unusual file ownership modifications outside customer web roots, unexpected symlinks within subscription directories, and suspicious activity involving Backup Manager restore operations. Reviewing privileged filesystem changes and authentication logs may help identify attempted exploitation.
Plesk credited security researchers Ali Mustafa, also known as rz1027, and abed1526 for responsibly reporting the vulnerability. The vendor advises customers to update Plesk Obsidian to the latest available build as soon as possible.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

