Description
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
Published: 2026-09-10
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation to Root
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a time‑of‑check/time‑of‑use race condition (CWE‑367) in the Plesk Backup Manager. It enables an attacker that can trigger a restore operation to create or replace a symlink that is later followed without proper ownership checks. The flaw permits arbitrary takeover of file or directory ownership, allowing the attacker to elevate privileges to the root user.

Affected Systems

All WebPros Plesk installations that include the Backup Manager component are affected. The advisory does not specify a particular version range, so any instance of Plesk running the vulnerable code prior to the fix should be considered at risk.

Risk and Exploitability

The severity is reflected in a CVSS score of 9.9, indicating a critical impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. Based on the description, it is inferred that the attack vector is local, requiring access to the Plesk environment to trigger a restore flow. Once the race is achieved, the attacker can gain root privileges by forcing ownership changes, making this a high‑risk issue for Plesk deployments.

Generated by OpenCVE AI on September 10, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Plesk patch that fixes the symlink race flaw as soon as it is available.
  • If the patch is not yet released, disable the Backup Manager feature or restrict access to backup filesinks that could be abused.
  • Implement host‑based defenses such as SELinux or AppArmor to restrict the backup process from following untrusted syml modifications or anomalies in backup operations and consider engaging a security audit for systems that manage backups.

Generated by OpenCVE AI on September 10, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Symlink Race Condition in Plesk Backup Manager Allows Local Privilege Escalation to Root

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
Weaknesses CWE-367
References
Metrics cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-10T18:18:54.741Z

Reserved: 2026-07-30T15:00:00.609Z

Link: CVE-2026-68488

cve-icon Vulnrichment

Updated: 2026-09-10T18:18:48.448Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T17:17:05.437

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-68488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:30:06Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition