CVE-2026-87886

9.5 CISA KEV

Acronis · Backup

Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.

Executive summary

This critical vulnerability in Acronis Backup is currently being exploited in the wild, necessitating immediate patching to prevent unauthorized privilege escalation.

Vulnerability

The flaw stems from insecure file permissions, classified as CWE-276, which allows an authenticated attacker with low privileges to achieve local privilege escalation without requiring user interaction.

Business impact

Successful exploitation of this vulnerability permits an attacker to elevate their privileges on the host system, potentially gaining full administrative control over the affected server. Given the CVSS score of 9.5, this represents a critical risk to data confidentiality, integrity, and availability. The verified active exploitation in the wild further elevates the urgency of this advisory for all organizations utilizing these backup extensions.

Remediation

Immediate Action: Update the Acronis Backup plugin for cPanel & WHM to version 1.9.3 HF3 and the Acronis Backup extension for Plesk to version 1.8.11.

Proactive Monitoring: Review system logs for unauthorized user account modifications or unusual escalation attempts originating from the web server service account.

Compensating Controls: Restrict access to the cPanel and Plesk administrative interfaces to trusted IP addresses only, and implement strict file system auditing to detect unauthorized permission changes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The presence of this vulnerability in the CISA Known Exploited Vulnerabilities catalog confirms that attackers are actively targeting these systems. Administrators must prioritize the deployment of the specified patches immediately to safeguard their infrastructure against potential compromise and unauthorized escalation of privileges.

More Acronis CVEs

History

  1. Disclosed CVE record published
  2. Added to CISA KEV confirmed active exploitation
  3. Collected by CVE Brief via github
  4. Analyst report written
  5. Analyst report updated
  6. Published in the daily brief kev section