Impact
The vulnerability is a time‑of‑check/time‑of‑use race condition (CWE‑367) in the Plesk Backup Manager. It enables an attacker that can trigger a restore operation to create or replace a symlink that is later followed without proper ownership checks. The flaw permits arbitrary takeover of file or directory ownership, allowing the attacker to elevate privileges to the root user.
Affected Systems
All WebPros Plesk installations that include the Backup Manager component are affected. The advisory does not specify a particular version range, so any instance of Plesk running the vulnerable code prior to the fix should be considered at risk.
Risk and Exploitability
The severity is reflected in a CVSS score of 9.9, indicating a critical impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. Based on the description, it is inferred that the attack vector is local, requiring access to the Plesk environment to trigger a restore flow. Once the race is achieved, the attacker can gain root privileges by forcing ownership changes, making this a high‑risk issue for Plesk deployments.
OpenCVE Enrichment