CVE-2026-68488

9.9

WebPros · Plesk

A TOCTOU race condition in Plesk allows local users to escalate privileges to root by manipulating symlinks during file operations.

Executive summary

A critical race condition vulnerability in WebPros Plesk allows authenticated users to gain full root-level control over the host system.

Vulnerability

This vulnerability is a Time-of-check Time-of-use (TOCTOU) race condition (CWE-367) occurring within the Backup Manager during restore operations. An attacker with low-level authenticated access can exploit this flaw to follow insecure symlinks, facilitating arbitrary file or directory ownership takeover.

Business impact

The ability to escalate privileges to root represents the highest level of security risk, as it grants an attacker complete control over the server environment. This vulnerability compromises the confidentiality, integrity, and availability of all hosted data and applications. Given the CVSS score of 9.9, this issue must be prioritized immediately to prevent total system compromise and potential lateral movement within the infrastructure.

Remediation

Immediate Action: Review the official WebPros support advisory at the provided reference link to determine if a specific patch or configuration workaround is available for your build. If no patch is currently available, restrict access to the Backup Manager functionality to trusted administrative users only.

Proactive Monitoring: Monitor system logs for unauthorized changes to file ownership or unusual symlink creation activity, particularly during backup restoration tasks.

Compensating Controls: Implement strict file system permissions and ensure that backups are restored in isolated, non-production environments whenever possible to minimize the impact of potential race conditions.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for total system takeover, administrators should treat this vulnerability as a high-priority remediation item. Please monitor the official Plesk support channels closely for the release of a definitive patch and apply it to all affected production servers as soon as it becomes available.

More WebPros CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources