CVE-2026-68487: Path Traversal
Published Sep 10, 2026
·Updated
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Affected Software
1 affected component
Plesk Plesk Backup Manager
Event History
Sep 10, 2026
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated as a customer. Exploitation does not require user interaction and is rated as low complexity over the network.
2
What is the likely security impact if exploitation succeeds?
The issue permits arbitrary file writes as root. The supplied vector indicates high impact to confidentiality, integrity, and availability, with scope changed.