CVE-2026-87886
9.5 CISA KEVAcronis · Backup
Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.
Executive summary
This critical vulnerability in Acronis Backup is currently being exploited in the wild, necessitating immediate patching to prevent unauthorized privilege escalation.
Vulnerability
The flaw stems from insecure file permissions, classified as CWE-276, which allows an authenticated attacker with low privileges to achieve local privilege escalation without requiring user interaction.
Business impact
Successful exploitation of this vulnerability permits an attacker to elevate their privileges on the host system, potentially gaining full administrative control over the affected server. Given the CVSS score of 9.5, this represents a critical risk to data confidentiality, integrity, and availability. The verified active exploitation in the wild further elevates the urgency of this advisory for all organizations utilizing these backup extensions.
Remediation
Immediate Action: Update the Acronis Backup plugin for cPanel & WHM to version 1.9.3 HF3 and the Acronis Backup extension for Plesk to version 1.8.11.
Proactive Monitoring: Review system logs for unauthorized user account modifications or unusual escalation attempts originating from the web server service account.
Compensating Controls: Restrict access to the cPanel and Plesk administrative interfaces to trusted IP addresses only, and implement strict file system auditing to detect unauthorized permission changes.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The presence of this vulnerability in the CISA Known Exploited Vulnerabilities catalog confirms that attackers are actively targeting these systems. Administrators must prioritize the deployment of the specified patches immediately to safeguard their infrastructure against potential compromise and unauthorized escalation of privileges.
More Acronis CVEs
History
- Disclosed CVE record published
- Added to CISA KEV confirmed active exploitation
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief kev section