Description
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Published: 2026-09-10
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Root File Write
Action: Immediate Patch
AI Analysis

Impact

Based on the description, the vulnerability resides in Plesk’s Backup Manager component, where an authenticated customer can exploit a path traversal flaw in the upload process to write an arbitrary file anywhere on the host as root. The description indicates that the flaw may enable replacement of critical system files or injection of malicious payloads, which could compromise system integrity and potentially lead to full system compromise.

Affected Systems

All WebPros Plesk installations are affected, but the data does not specify which versions are vulnerable; affected version ranges are unavailable.

Risk and Exploitability

Based on the description, an attacker who is an authenticated customer may write an arbitrary file as root. With a CVSS score of 9.9 the flaw is critical. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the severity remains high because the attacker only needs valid customer credentials to exercise unlimited file system write access as root; this high privilege level makes the vulnerability an attractive target for threat actors.

Generated by OpenCVE AI on September 11, 2026 at 03:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the official Plesk security update that fixes the Backup Manager path traversal flaw as soon as it is released.
  • If no patch is available, enforce strict input validation for backup uploads, ensuring that any file paths are sanitized and verified against CWE‑36 requirements to prevent path traversal.
  • Limit the Backup Manager upload functionality to trusted administrator users only, blocking access from regular customers or untrusted endpoints.
  • Implement file integrity monitoring or automated alerts for critical system directories so that any unauthorized write attempts can be detected and investigated promptly.

Generated by OpenCVE AI on September 11, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros plesk
Vendors & Products Webpros
Webpros plesk

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Arbitrary Root File Write in Plesk Backup Manager

Thu, 10 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Arbitrary Root File Write in Plesk Backup Manager

Thu, 10 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Plesk Backup Manager Path Traversal Allows Root File Write

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Plesk Backup Manager Path Traversal Allows Root File Write

Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Weaknesses CWE-36
References
Metrics cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-10T18:08:51.400Z

Reserved: 2026-07-30T15:00:00.608Z

Link: CVE-2026-68487

cve-icon Vulnrichment

Updated: 2026-09-10T18:08:48.771Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T17:17:05.310

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-68487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:45:06Z

Weaknesses
  • CWE-36

    Absolute Path Traversal