CVE-2026-68488
Received Received - Intake

TOCTOU Race Condition in Plesk Leads to Root Privilege Escalation

Vulnerability report for CVE-2026-68488, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: HackerOne

Description

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
plesk backup_manager to 18.0.80.7 (exc)
plesk backup_manager to 18.0.79.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Time-of-check Time-of-use (TOCTOU) race condition in Plesk that allows insecure symlink following. It enables local privilege escalation to root by exploiting a flaw during the restoration of subscription content in the Backup Manager. An attacker with Panel and FTP access can change ownership of files outside their subscription, potentially gaining full root access on the server.

Detection Guidance

Check your Plesk version using the command 'plesk version' in the terminal. If your version is 18.0.80.6 or earlier, or 18.0.79.10 or earlier, your system is vulnerable. Additionally, review file ownership changes in system logs during backup operations to detect suspicious activity.

Impact Analysis

If you are a Plesk user with Linux versions 18.0.80.6 or earlier, or 18.0.79.10 and earlier, an attacker with Panel and FTP access to your subscription could escalate privileges to root. This could allow them to take full control of your server, access sensitive data, or perform unauthorized actions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements like GDPR or HIPAA. Unauthorized root access may result in data breaches, loss of data integrity, or failure to meet regulatory obligations for data protection and access controls.

Mitigation Strategies

Update Plesk to the latest patched versions: 18.0.80.7 or later for 18.0.80.x, and 18.0.79.11 or later for 18.0.79.x. Remove unnecessary FTP and Panel access for subscriptions to reduce attack surface until updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68488. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart