Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-68487: Plesk Backup Manager allows users to write file as root

CVE-2026-68487 · published 29 days ago
Summary

Plesk’s Backup Manager can be tricked by a signed‑in customer to place files anywhere on the server with full administrator rights. This could let an attacker add malicious programs or change important system files. Install the latest Plesk update and limit who can access the backup feature.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
webpros plesk <= 18.0.80.6
Original advisory text
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-36Absolute Path Traversal
Timeline
Published10 Sep 2026
Updated7 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-68487 · MITRE
Track software like this
Free during beta