CVE-2026-41220
7.8Acronis · DeviceLock DLP, Cyber Protect Cloud Agent
Acronis DeviceLock DLP and Cyber Protect Cloud Agent are vulnerable to local privilege escalation due to improper input validation, allowing authenticated users to gain elevated system rights.
Executive summary
A local privilege escalation vulnerability in Acronis DeviceLock DLP and Cyber Protect Cloud Agent poses a significant risk of unauthorized system-level access for local attackers.
Vulnerability
This vulnerability involves a flaw in input validation, classified as CWE-787, which allows an attacker with existing low-privileged local access to escalate their privileges to a higher level.
Business impact
The ability for a local user to escalate privileges represents a critical security failure, as it allows attackers to bypass standard permission boundaries. With a CVSS score of 7.8, this vulnerability enables full system compromise, potentially leading to unauthorized data access, the installation of malicious software, or the disruption of security operations within the organization.
Remediation
Immediate Action: Update Acronis DeviceLock DLP to build 9.0.93212 or later, and update the Acronis Cyber Protect Cloud Agent to build 42183 or later.
Proactive Monitoring: Review system logs for unusual process execution or attempts to access administrative directories by low-privileged service accounts.
Compensating Controls: Implement strict principle of least privilege policies on all endpoints to limit the number of users capable of executing local code on machines where these agents are deployed.
Exploitation status
Public Exploit Available: exploit_available (unknown)
Analyst recommendation
Given the potential for complete system compromise, organizations should prioritize the deployment of the provided security patches across all affected Windows environments. Administrators must ensure that these updates are applied to both DeviceLock DLP and the Cyber Protect Cloud Agent immediately to prevent local attackers from abusing this input validation flaw to gain administrative control.
More Acronis CVEs
Sources
Originally found and disclosed by Kolja Grassmann (Neodyme AG) (mailto:contact@neodyme.io), per the CVE Program record.
- SEC-10296 Vendor advisory