Privilege Escalation Vulnerability in Plesk by Plesk International
CVE-2026-68488
9.9CRITICAL
What is CVE-2026-68488?
A race condition in the Plesk Backup Manager can lead to an insecure symlink following, enabling local privilege escalation. This vulnerability allows an attacker to gain unauthorized root access by taking ownership of arbitrary files or directories. Proper safeguards against race conditions are essential to securing the application and preventing unauthorized privilege escalation.
Affected Version(s)
Plesk 0 <= 18.0.80.6
Plesk 0 <= 18.0.79.10
