Acronis Patches High-Severity Privilege Escalation Flaw in cPanel & Plesk Backup Tools
Acronis has released security updates to address a high-severity local privilege-escalation vulnerability (CVE-2026-87886) in its Backup plugin for cPanel & WHM and Backup extension for Plesk. The flaw, rated 7.8 on the CVSS scale, stems from insecure file permissions in Linux-based Acronis backup components, classified as CWE-276 (incorrect default permissions).
Exploitation requires local access with low-level privileges but no user interaction. Successful attacks could allow threat actors to escalate privileges, compromising system confidentiality, integrity, and availability. Attackers with initial access via compromised accounts, weak credentials, or vulnerable web applications could leverage the flaw to access backup data, system files, or other customer accounts on shared hosting infrastructure.
Acronis confirmed limited, targeted exploitation in the wild but warned that public disclosure and patch availability may increase attack risks. The vulnerability was patched in:
- Acronis Backup plugin for cPanel & WHM (version 1.9.3 HF3)
- Acronis Backup extension for Plesk (version 1.8.11)
Managed service providers and hosting companies are urged to prioritize updates, as cPanel and Plesk servers often host multiple customer workloads. Security teams should monitor for unauthorized local access, unexpected privilege changes, and suspicious activity in Acronis-related files or directories.
For organizations unable to patch immediately, Acronis recommends restricting local access, limiting shell permissions, and isolating backup infrastructure from standard hosting environments. The vendor’s advisory confirms the fix addresses one high-severity flaw, with exploitation already detected.
Source: https://cybersecuritynews.com/acronis-plugin-vulnerability-exploited/
Acronis TPRM report: https://www.rankiteo.com/company/acronis
cPanel & WHM TPRM report: https://www.rankiteo.com/company/cpanel
Plesk TPRM report: https://www.rankiteo.com/company/plesk
"id": "pleacrcpa1789547109",
"linkid": "plesk, acronis, cpanel",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Managed service providers, '
'hosting companies, and users of '
'cPanel & Plesk with Acronis '
'Backup plugin/extension',
'industry': 'Cybersecurity, Backup Solutions',
'name': 'Acronis',
'type': 'Vendor'}],
'attack_vector': 'Local Access',
'data_breach': {'sensitivity_of_data': 'High (backup data, system files, '
'customer accounts)',
'type_of_data_compromised': 'Backup data, system files, '
'customer account data'},
'description': 'Acronis has released security updates to address a '
'high-severity local privilege-escalation vulnerability '
'(CVE-2026-87886) in its Backup plugin for cPanel & WHM and '
'Backup extension for Plesk. The flaw, rated 7.8 on the CVSS '
'scale, stems from insecure file permissions in Linux-based '
'Acronis backup components, classified as CWE-276 (incorrect '
'default permissions). Exploitation requires local access with '
'low-level privileges but no user interaction. Successful '
'attacks could allow threat actors to escalate privileges, '
'compromising system confidentiality, integrity, and '
'availability. Attackers with initial access via compromised '
'accounts, weak credentials, or vulnerable web applications '
'could leverage the flaw to access backup data, system files, '
'or other customer accounts on shared hosting infrastructure.',
'impact': {'data_compromised': 'Backup data, system files, customer accounts '
'on shared hosting infrastructure',
'operational_impact': 'Compromised system confidentiality, '
'integrity, and availability',
'systems_affected': 'Acronis Backup plugin for cPanel & WHM, '
'Acronis Backup extension for Plesk'},
'initial_access_broker': {'entry_point': 'Compromised accounts, weak '
'credentials, vulnerable web '
'applications'},
'investigation_status': 'Limited, targeted exploitation confirmed in the wild',
'post_incident_analysis': {'corrective_actions': 'Patches released, security '
'best practices recommended '
'(restricting access, '
'isolation, monitoring)',
'root_causes': 'Insecure file permissions '
'(CWE-276) in Linux-based Acronis '
'backup components'},
'recommendations': 'Prioritize updates, restrict local access, limit shell '
'permissions, isolate backup infrastructure, monitor for '
'unauthorized activity',
'references': [{'source': 'Acronis Advisory'}],
'response': {'communication_strategy': 'Vendor advisory issued, urging '
'prioritization of updates',
'containment_measures': 'Security updates released, restricting '
'local access, limiting shell '
'permissions, isolating backup '
'infrastructure',
'enhanced_monitoring': 'Monitoring for unauthorized local '
'access, unexpected privilege changes, '
'and suspicious activity in '
'Acronis-related files/directories',
'network_segmentation': 'Isolating backup infrastructure from '
'standard hosting environments',
'remediation_measures': 'Patches applied in Acronis Backup '
'plugin for cPanel & WHM (version 1.9.3 '
'HF3) and Acronis Backup extension for '
'Plesk (version 1.8.11)'},
'stakeholder_advisories': 'Managed service providers and hosting companies '
'urged to prioritize updates',
'title': 'Acronis Patches High-Severity Privilege Escalation Flaw in cPanel & '
'Plesk Backup Tools',
'type': 'Privilege Escalation',
'vulnerability_exploited': 'CVE-2026-87886 (CWE-276 - Incorrect Default '
'Permissions)'}