{"id":"CVE-2026-68487","title":"Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.","summary":"Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-36"],"vendor":"WebPros","product":"Plesk","affected":["Plesk <= 18.0.80.6","Plesk <= 18.0.79.10"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T18:08:44.436403Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T18:08:51.400Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-68487","references":[{"url":"https://support.plesk.com/hc/en-us/articles/43248841638551-Vulnerability-in-Plesk-s-Backup-Manager-unsigned-backup-header-allows-path-traversal"}],"tags":["cve.org"],"epss":0.00407,"epssPercentile":0.34661,"ingestedAt":"2026-09-11T16:45:48.029Z","slug":"CVE-2026-68487","body":"## Overview\n\nPath traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.\n\n## Affected\n\n- `Plesk <= 18.0.80.6`\n- `Plesk <= 18.0.79.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":54.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}