SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-68488

CRITICAL · CVSS 9.9 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical race condition in Plesk allows local attackers to exploit a Time-of-check Time-of-use (TOCTOU) vulnerability, enabling them to gain root privileges through arbitrary file or directory ownership takeover. This flaw poses a significant risk to any systems running Plesk, particularly those with multi-user environments. Organizations utilizing Plesk should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-68488
Severity
CRITICAL
CVSS
9.9
EPSS
0.20%

Original NVD Description

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.