Junglewise Threat Intelligence

CVE-2026-68487: Plesk Backup Manager path traversal allows arbitrary file write

CVE-2026-68487 · Severity: critical · CVSS 9.9 · Published 2026-09-10

Vendors: Plesk.

Executive brief

Plesk's Backup Manager, a critical utility for backing up and restoring hosting environments, contains a path traversal vulnerability that allows authenticated customers to write arbitrary files to the system with root privileges. An attacker with customer-level access could exploit this during backup restore operations to gain complete control of the hosting server, compromising all hosted customer data and services.

Technical details

The vulnerability is a path traversal flaw in Plesk's Backup Manager that arises from insufficient validation of backup file paths during restore operations. An authenticated customer can craft malicious backup archives containing specially crafted file paths (e.g., containing "../" sequences) that bypass directory restrictions and write files to arbitrary locations on the filesystem. Because the Backup Manager process runs with root privileges, the attacker can overwrite system files, install backdoors, or modify configuration files. The vulnerability requires valid customer credentials and interaction with the backup restore functionality, but no other privileges are needed. Patches are available from Plesk.

Affected products

  • Plesk Backup Manager

Timeline

  • 2026-09-10: disclosed

References