Plesk disclosed CVE-2026-68488, a privilege-escalation flaw in Backup Manager for Plesk Obsidian on Linux. An authenticated low-privileged Plesk customer with FTP access can exploit a symlink race during subscription-content restore operations to change ownership of files outside their assigned subscription; because restores run with elevated privileges, exploitation can lead to root-level compromise of the server.
The vulnerability particularly endangers shared-hosting, managed-server, and other multi-tenant deployments. Plesk for Windows is unaffected; administrators should upgrade affected Linux installations to 18.0.80.7 or later or 18.0.79.11 or later, then investigate anomalous restore activity, symlinks in subscription directories, unexpected ownership changes, privileged filesystem modifications, and authentication logs.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Plesk released fixes for CVE-2026-68488, a symlink race condition in Backup Manager restore operations that could let an authenticated Plesk customer with FTP access alter ownership outside their subscription and potentially gain root access on affected Linux servers. The fixes are included in Plesk Obsidian 18.0.80.7 and later and 18.0.79.11 and later; Plesk for Windows is unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.