Description
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Published: 2026-09-10
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Plesk’s Backup Manager contains a path traversal flaw that allows an authenticated customer to write an arbitrary file to any location on the server with root privileges. This vulnerability can be leveraged to replace critical system files, plant malicious scripts, or otherwise take full control of the affected system, effectively giving an attacker remote code execution capabilities.

Affected Systems

The flaw affects Plesk installations from WebPros. The exact versions affected were not detailed in the advisory, so all current and older releases should be considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9.9 marks this as critical, and although the EPSS score is unavailable, the high magnitude indicates a serious threat. The attack requires authentication as a customer, but once authenticated it can result in root-level file writes, making exploitation highly valuable to attackers. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate mitigation.

Generated by OpenCVE AI on September 10, 2026 at 18:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Plesk to a version that includes the approved backup manager fix or apply the vendor‑issued patch for the path traversal issue.
  • Disable or restrict the Backup Manager functionality for accounts that do not require it, limiting the attack surface.
  • After applying the fix, audit backup configurations to confirm no residual writable paths exist and verify that proper file permissions remain enforced.

Generated by OpenCVE AI on September 10, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Plesk Backup Manager Path Traversal Allows Root File Write

Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Weaknesses CWE-36
References
Metrics cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-10T18:08:51.400Z

Reserved: 2026-07-30T15:00:00.608Z

Link: CVE-2026-68487

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T17:17:05.310

Modified: 2026-09-10T17:17:05.310

Link: CVE-2026-68487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:15:06Z

Weaknesses
  • CWE-36

    Absolute Path Traversal