SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-68487

CRITICAL · CVSS 9.9 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A path traversal vulnerability in Plesk's Backup Manager allows authenticated users to write arbitrary files with root privileges, potentially compromising the entire system. This critical flaw poses a significant risk to any organization using Plesk for web hosting and management, especially those with multiple customer accounts. Administrators should prioritize immediate patching and review access controls to mitigate potential exploitation.

CVE
CVE-2026-68487
Severity
CRITICAL
CVSS
9.9
EPSS
0.36%

Original NVD Description

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.