CVE-2026-41952
7.8Acronis · DeviceLock DLP, Cyber Protect Cloud Agent
A local privilege escalation vulnerability exists in Acronis DeviceLock DLP and Cyber Protect Cloud Agent due to improper input validation, allowing authenticated local users to gain elevated privileges.
Executive summary
A local privilege escalation vulnerability in Acronis DeviceLock DLP and Cyber Protect Cloud Agent allows low-privileged local users to achieve full system compromise.
Vulnerability
This vulnerability is caused by improper input validation (CWE-123). An attacker with local access and low privileges can exploit this flaw to execute arbitrary code with system-level permissions.
Business impact
The vulnerability carries a CVSS score of 7.8, which reflects a high severity rating due to the potential for total system compromise. Successful exploitation allows a local user to bypass security controls, leading to unauthorized data access, modification, or complete system takeover. This poses a significant threat to organizational data integrity and system availability.
Remediation
Immediate Action: Update Acronis DeviceLock DLP to build 9.0.93212 or later, and update Acronis Cyber Protect Cloud Agent to build 42183 or later.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access sensitive system directories or unexpected execution of administrative processes by non-privileged accounts.
Compensating Controls: Restrict local user access to the affected systems and ensure that only authorized personnel have the ability to execute local commands on endpoints running the vulnerable software.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high impact of local privilege escalation, organizations should prioritize the deployment of the provided patches across all affected Windows endpoints. Failure to remediate this vulnerability leaves systems susceptible to full compromise by any local user, which could facilitate lateral movement or further malicious activity within the network.
More Acronis CVEs
Sources
Originally found and disclosed by @oriotie (https://hackerone.com/oriotie), per the CVE Program record.
- SEC-7790 Vendor advisory