Published September 15, 2026 - New York. Plesk has patched a critical symlink race condition in its Backup Manager, tracked as CVE-2026-68488, that can let a low-privileged authenticated customer escalate privileges and gain full root access on affected Linux servers, alongside a companion path-traversal flaw, CVE-2026-68487, that likewise ends in arbitrary file writes as root.
At a glance
- CVE-2026-68488 is a Time-of-check Time-of-use race condition with insecure symlink following in the Backup Manager restore workflow, enabling local privilege escalation to root via arbitrary file writes.
- Affected products are Plesk Obsidian for Linux 18.0.80.6 and earlier and 18.0.79.10 and earlier; Plesk for Windows is not affected.
- Fixed builds 18.0.80.7 and 18.0.79.11 shipped around September 10, 2026, also closing CVE-2026-68487, a path traversal letting an authenticated customer write arbitrary files as root.
- Hosting-industry roundups rate both flaws 9.9. Exploitation requires a valid subscription account, so this is not unauthenticated RCE - but success means full server compromise.
- September has been an unusually heavy month for hosting-stack security overall, with parallel fixes due for cPanel, WHMCS, WordPress and CloudLinux.
Data last verified September 15, 2026 from the Plesk security advisories, CVE.org, Rapid7 and Cybersecurity News.
Quick Answer
If you administer Plesk on Linux, update to 18.0.80.7 or 18.0.79.11 immediately. The vulnerability does not let a random internet attacker walk in - it requires an authenticated customer account on the server - but it converts a low-privileged tenant into root on the whole box, which in shared hosting means every site, database and email account on that machine. Because Backup Manager restores are routine operations that tenants can trigger, the attack surface is real for any provider running unpatched builds. Patches have been available since September 10, and there is no good reason to wait.
What happened: the Backup Manager flaws
Plesk, the hosting control panel platform owned by WebPros, released security advisories around September 10, 2026 covering two critical flaws in its Backup Manager. The first, CVE-2026-68488, is a Time-of-check Time-of-use race condition that leads to insecure symlink following during the restore of subscription content. In plain terms: when Backup Manager unpacks or restores files, there is a window between the moment the software checks a file path and the moment it writes to it. An attacker who wins that race by planting a symlink can redirect a privileged write to a location of their choosing - a classic local privilege escalation that ends with arbitrary, root-owned files landing on the host filesystem and full server compromise.
The second flaw, CVE-2026-68487, is a path traversal in the same Backup Manager component that lets an authenticated customer write arbitrary files as root directly, without needing to win any race. Hosting-industry roundups of the advisories rate both issues 9.9. Plesk credited researchers Ali Mustafa, known as rz1027, and abed1526 for responsibly disclosing the path-traversal flaw. Both vulnerabilities live in the workflow used to restore content belonging to a customer subscription - exactly the kind of feature that multi-tenant hosting providers expose to their customers every day.
The context makes this more than a routine patch. September 2026 has been described in hosting-security roundups as an unusually heavy month: the same to-do list for providers includes a CVSS 9.9 SQL injection in cPanel EmailTrack that can end in root access, an unauthenticated WHMCS remote code execution fixed on September 3, the actively exploited wp2shell WordPress RCE chain, and CloudLinux kernel updates covering seven local root exploits. The Plesk pair belongs on that same emergency-change list.
Who is affected
The primary victims are hosting providers, web agencies, managed service providers and enterprises that run Plesk Obsidian on Linux and give customers or resellers their own subscriptions. The risk scales with how much you trust your tenants: on a server where customers are anonymous signups, a single malicious account is one registration away from root. On internally managed Plesk servers with no external tenants, exposure is lower but not zero, since any compromised customer-level account becomes a launchpad.
Not affected: Plesk for Windows installations, and any Linux server already running 18.0.80.7 or 18.0.79.11 or later. Note that the 18.0.79 branch and the 18.0.80 branch have separate fixed builds, so administrators must know which release line they run before patching.
How to check if you are affected
Log into the Plesk admin interface and check the current version under Server Management, or run the Plesk version command from the shell. Anything at or below 18.0.80.6 on the 18.0.80 line, or at or below 18.0.79.10 on the 18.0.79 line, is vulnerable.
Beyond version checks, admins reviewing potentially exposed servers should look for signs of prior abuse of the restore workflow: unexpected root-owned files, unusual SUID binaries, unfamiliar local accounts or SSH keys added to root, and restore or backup jobs in the action log that tenants cannot explain. None of these prove exploitation, but any of them warrants deeper investigation before you declare the box clean.
What to do next: mitigation checklist
Work through this list in order:
- Update Plesk Obsidian to 18.0.80.7 or later, or 18.0.79.11 or later, depending on your release branch. Hosting roundups recommend running the Plesk installer with the select-release-current and update-installed options to pull all current fixes.
- Verify the installed version after updating, and confirm the Backup Manager restore workflow completes normally on a test subscription.
- Audit which customer and reseller roles can trigger subscription-content restores, and tighten those permissions where the business allows.
- Rotate credentials on the server: admin passwords, database administrator accounts, and any SSH keys used for management.
- Review the server for the indicators above - unexpected root-owned files, SUID binaries, unknown accounts - and treat anything suspicious as an incident.
- While you are in maintenance mode, apply the rest of September's hosting-stack fixes: cPanel, WHMCS, WordPress core and plugins, and CloudLinux kernel updates.
- Re-run vulnerability scans against the Plesk management interface to confirm the CVEs no longer flag.
The Plesk flaws are a quiet reminder that control panels are the real operating system of shared hosting. Every feature exposed to a tenant - even something as mundane as restoring a backup - is a privilege boundary, and September's patch batch shows vendors are still finding ways those boundaries leak.






