Vulnerabilities & PatchesEmerging1 src
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers.
Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations.
The issue affects Plesk Obsidian installations running Plesk for Linux versions 18. 0. 80. 6 and earlier, as well as 18. 0. 79. 10 and earlier. Plesk for Windows is not affected.
According to Plesk, the vulnerability exists in the Backup Manager workflow used to restore content belonging to a customer subscription. A user with ordinary access to the Plesk Panel and FTP access to their own hosted subscription may exploit a race condition involving symbolic links (symlinks).
Symlinks are filesystem objects that point to another file or directory.