CVE-2026-68488

Summary

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

Affected Software

VendorProductVersion RangeStatus
WebProsPlesk0 <= 18.0.80.6affected
WebProsPlesk0 <= 18.0.79.10affected

Weaknesses

  • CWE-367: CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References