CVE-2026-68487
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-36
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- WebPros Plesk
Weakness type
Related vulnerabilities
- CVE-2026-82092 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-88288 — GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation
- CVE-2026-68896 — Microsoft Windows Search Component Elevation of Privilege Vulnerability
- CVE-2026-69612 — Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2026-47630 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an...
- CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an...
- CVE-2026-46345 — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
- CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs