CVE-2026-28727
7.8Acronis · Cyber Protect, Cyber Protect Cloud Agent, True Image
A local privilege escalation vulnerability in Acronis software on macOS stems from insecure Unix socket permissions, allowing local users to gain elevated privileges.
Executive summary
Acronis macOS products are vulnerable to local privilege escalation, which could allow a local attacker to gain full control over the affected system.
Vulnerability
This vulnerability is caused by improper permissions assigned to Unix sockets, which is categorized as CWE-276. A local attacker with low privileges can exploit this flaw to execute actions with higher authority on the system.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk due to the potential for total compromise of confidentiality, integrity, and availability. Successful exploitation allows a local user to bypass security controls, potentially leading to unauthorized data access, system disruption, or the installation of malicious software.
Remediation
Immediate Action: Update all affected Acronis products to the specific build versions listed above, as these releases contain the necessary security patches for the Unix socket permissions.
Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized attempts to access or modify system files that would normally be restricted to privileged accounts.
Compensating Controls: Ensure that access to the local machine is strictly limited to authorized personnel and implement principle of least privilege for all local user accounts to minimize the potential impact of an escalation attempt.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high impact of this vulnerability, administrators should prioritize updating all Acronis installations on macOS platforms to the patched build versions. Failure to remediate this issue leaves systems susceptible to privilege escalation by any local user, which could result in a full system takeover.
More Acronis CVEs
Sources
Originally found and disclosed by @aiqitut (https://hackerone.com/aiqitut), per the CVE Program record.
- SEC-9408 Vendor advisory