CVE-2026-33092
7.8Acronis · True Image
Acronis True Image on macOS is vulnerable to local privilege escalation caused by the improper handling of environment variables.
Executive summary
A local privilege escalation vulnerability in Acronis True Image for macOS allows a local attacker with standard privileges to gain elevated control over the system.
Vulnerability
This vulnerability, categorized as CWE-15, stems from improper handling of environment variables. A locally authenticated user with low privileges can exploit this flaw to execute code or perform actions with higher privileges on the host system.
Business impact
The ability for a local user to escalate privileges represents a significant security risk, as it allows for the potential compromise of system integrity, confidentiality, and availability. With a CVSS score of 7.8, this high-severity flaw could allow an attacker to bypass standard security controls, access sensitive backup data, or disable security software. Such unauthorized access can lead to total system takeover, which may result in severe operational disruption and data loss.
Remediation
Immediate Action: Update all installations of Acronis True Image on macOS to build 42571 (for OEM) or 42902 (for standard) or later versions immediately.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected changes to system environment variables initiated by non-administrative users.
Compensating Controls: Restrict local user access to the system and ensure that the principle of least privilege is strictly enforced to limit the potential impact of local exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high-severity nature of this privilege escalation vulnerability, organizations should prioritize patching their Acronis True Image environments. Applying the vendor-supplied updates is the only effective way to fully remediate the underlying logic flaw. Administrators should verify the build numbers on all macOS endpoints to ensure they are no longer running affected versions.
More Acronis CVEs
Sources
Originally found and disclosed by @aiqitut (https://hackerone.com/aiqitut), per the CVE Program record.
- SEC-9407 Vendor advisory