CVE-2026-68487

Summary

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Affected Software

VendorProductVersion RangeStatus
WebProsPlesk0 <= 18.0.80.6affected
WebProsPlesk0 <= 18.0.79.10affected

Weaknesses

  • CWE-36: CWE-36 Absolute Path Traversal

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References