Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access
A newly disclosed vulnerability in Plesk Backup Manager could allow a low-privileged customer to escalate privileges and obtain full root access to a vulnerable Linux server.

Tracked as CVE-2026-68488, the flaw is caused by a symlink race condition during subscription-content restoration. Plesk says an attacker with ordinary Panel and FTP access to their own subscription can potentially change ownership of files or directories outside that subscription.
Affected Versions
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| Plesk for Linux | 18.0.80.6 and earlier | 18.0.80.7 |
| Plesk for Linux | 18.0.79.10 and earlier | 18.0.79.11 |
| Plesk for Windows | Not affected | — |
Plesk's advisory confirms that Windows installations are not affected.
How the Attack Works
The vulnerability occurs during the restoration of subscription content.
An attacker with access to their own Plesk subscription can exploit a race condition involving symbolic links. By manipulating the restoration process, the attacker may cause Plesk to operate on a file or directory outside their authorized subscription.
This can ultimately allow the attacker to obtain ownership of privileged files and escalate their permissions to root.
Attack chain:
Low-privileged account → Malicious symlink → Backup restoration race condition → Unauthorized file ownership → Privilege escalation → Root access
Why Root Access Is Serious
Successful exploitation could give an attacker control over the underlying server rather than just their individual hosting account.
Depending on the server configuration, an attacker with root access could potentially:
- Modify system files
- Access other customers' websites and data
- Steal credentials and secrets
- Install malware or persistent backdoors
- Modify hosted applications
- Access databases
- Disable security controls
- Use the server for further attacks
For shared-hosting environments, the impact could be particularly serious because a single compromised customer account could potentially become a stepping stone to other hosted environments.
Recommended Actions
Plesk customers should update affected Linux installations immediately to the appropriate fixed release.
Security teams should also review:
- Backup Manager activity and restoration logs
- Unexpected file ownership changes
- Suspicious symbolic links
- New privileged files or processes
- Unexpected modifications outside customer directories
- Unusual administrative or SSH activity
If exploitation is suspected, administrators should investigate the server for persistence and unauthorized changes rather than simply applying the patch.
The vulnerability highlights a broader risk in hosting-control panels: tenant isolation is only as strong as the privileged operations performed behind the management interface.
Organizations running Plesk for Linux should prioritize the available security updates, particularly on shared or multi-tenant hosting servers.
SEO Meta Description:
A critical Plesk Backup Manager flaw, CVE-2026-68488, allows low-privileged Linux hosting users to exploit a symlink race and potentially gain root access.
Related reporting
Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens
Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.
Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Code Feature
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could allow a nearby attacker to execute unauthorized code or access information stored on the console.
China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor
China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.


