Executive brief
Plesk is a web hosting control panel that manages servers and applications for hosting providers. A race condition vulnerability in Plesk's backup restoration process allows a local user to exploit a window of time between checks and file operations to create malicious symlinks, leading to unauthorized root-level access and complete server compromise.
Technical details
The vulnerability is a Time-of-check Time-of-use (TOCTOU) race condition in Plesk's symlink handling, specifically triggered during backup restore operations. An attacker with local access can exploit the gap between the security check that validates a path or file and the subsequent file operation to redirect writes to arbitrary locations via symlink substitution. By gaining arbitrary file and directory ownership takeover, an attacker can escalate privileges to root. The attack requires local access but does not require prior authentication or elevated privileges to initiate. Patches are available from Plesk via their support portal.
Affected products
- Plesk Plesk
Timeline
- 2026-09-10: disclosed