CVE-2026-28710
8.1Acronis · Cyber Protect 17
Acronis Cyber Protect 17 is vulnerable to sensitive information disclosure and data manipulation due to improper authentication mechanisms.
Executive summary
An improper authentication vulnerability in Acronis Cyber Protect 17 allows unauthenticated attackers to potentially disclose or manipulate sensitive system information.
Vulnerability
The vulnerability, categorized under CWE-1390, stems from improper authentication handling. This flaw allows an unauthenticated remote attacker to bypass security controls and interact with sensitive data or perform unauthorized operations.
Business impact
Successful exploitation of this vulnerability could lead to the exposure of confidential business data or unauthorized modification of system configurations. Given the CVSS score of 8.1, the risk is classified as High, as it provides an attacker the capability to compromise the integrity and confidentiality of the affected backup and security infrastructure.
Remediation
Immediate Action: Update Acronis Cyber Protect 17 to build 41186 or later immediately to resolve the authentication vulnerability.
Proactive Monitoring: Review system access logs for anomalous entry patterns or unexpected administrative actions that deviate from established baselines.
Compensating Controls: Implement network segmentation and restrict access to the management interface of the backup software to trusted IP addresses only, thereby limiting the exposure to unauthenticated attackers.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this issue necessitates prompt action to secure the backup environment. Administrators should verify their current build version against the vendor advisory and apply the update to build 41186 as soon as possible to prevent potential unauthorized data access or manipulation.
More Acronis CVEs
Sources
- SEC-9137 Vendor advisory