A newly disclosed vulnerability in Plesk Backup Manager enables low-privileged users to escalate privileges and gain full root access on affected Linux servers This article explores vulnerability plesk backup. . This flaw arises from a symlink race condition during subscription-content restore operations, impacting Plesk Obsidian installations running Plesk for Linux versions 18.0.80.6 and earlier, as well as 18.0.79.10 and earlier.
An ordinary user with access to the Plesk Panel and FTP can exploit a race condition involving symbolic links (symlinks). An attacker could manipulate a path during the restore process, changing ownership of files or directories outside the attacker's subscription. CVE-2026-68488 breaks this security boundary by potentially allowing a customer account to affect files outside its own hosting environment.
Administrators should prioritize patching internet-facing and multi-tenant Plesk servers, especially systems where customers have FTP access and can trigger backup or restore-related functionality. Hosting providers must scrutinize Plesk user accounts, subscription permissions, and recent restore activities for any unusual ownership changes. Security teams should look for unusual file ownership modifications outside customer web roots, unexpected symlinks within subscription directories, and suspicious backup manager restore operations.












