CVE-2026-68487

9.9

WebPros · Plesk

A path traversal vulnerability in the Plesk Backup Manager allows an authenticated customer to perform arbitrary file writes with root privileges.

Executive summary

A critical path traversal vulnerability in WebPros Plesk allows an authenticated attacker to achieve arbitrary file writes as root, potentially leading to full system compromise.

Vulnerability

This is an absolute path traversal vulnerability (CWE-36) within the Backup Manager component. It allows an authenticated user with customer-level access to write arbitrary files to the underlying operating system with root-level permissions.

Business impact

The ability to write arbitrary files as the root user grants an attacker complete control over the Plesk server. This severity is underscored by the 9.9 CVSS score, reflecting a critical risk of total system compromise, data destruction, and unauthorized access to hosted environments.

Remediation

Immediate Action: Review the official WebPros support advisory for guidance on available patches or configuration changes to disable vulnerable Backup Manager functionality until a fix is applied.

Proactive Monitoring: Monitor server logs for unusual file write operations or unexpected modifications to system files, particularly those originating from the Backup Manager service.

Compensating Controls: Restrict access to the Plesk administrative and customer panels to trusted IP addresses using firewall rules, and ensure that the Backup Manager is only accessible to highly privileged, audited administrative accounts.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full administrative takeover of the server, organizations must prioritize this issue. Administrators should actively monitor the WebPros support portal for the release of security patches and apply them immediately upon availability to mitigate the risk of exploitation.

More WebPros CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources