Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges
Acronis patched CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in its cPanel & WHM backup plugin already exploited in targeted attacks.
Acronis released an urgent update for CVE-2026-87886 (CVSS 7.8), an insecure file permissions issue (CWE-276) in its Backup plugin for cPanel & WHM that lets a low-privileged local user elevate privileges on Linux servers. The company confirmed exploitation in limited, targeted attacks against cPanel & WHM deployments; the Plesk extension is also affected but no exploitation was observed there. Fixes are version 1.9.3 HF3 (build 1.9.3.1021 or later) for cPanel & WHM and 1.8.11 (build 1.8.11.638 or later) for Plesk.
- CVE-2026-87886 (CVSS 7.8, CWE-276) insecure file permissions allow local low-privileged attackers to escalate on Linux.
- Exploited in limited targeted attacks against cPanel & WHM deployments; no Plesk exploitation observed.
- Fixed in plugin build 1.9.3.1021 (1.9.3 HF3) and Plesk extension 1.8.11.638.
- Exploitation requires a prior foothold, making shared hosting and multi-tenant environments especially concerning.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87886 | NVD description · AI analysis pending | — | — | — | — | — |
Full article473 words · extracted from gbhackers.com · click to collapse
Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM on Linux. The company confirmed that attackers have already exploited this flaw in limited, targeted attacks against vulnerable deployments.
This vulnerability is tracked as CVE-2026-87886 and is described as an insecure file permissions issue that could allow a local, low-privileged attacker to gain elevated privileges on the affected Linux server. Acronis has assigned a CVSS score of 7.8 out of 10 to this vulnerability, categorizing it as high severity.
Acronis Backup Plugin Vulnerability
The flaw is detailed in Acronis advisory SEC-10986 and is associated with CWE-276, which refers to incorrect default permissions. Poorly managed file permissions can expose sensitive files, scripts, binaries, or configuration data to users who should not be able to modify or execute them.
According to the CVSS vector, exploitation requires local access and low privileges but no user interaction. Successful exploitation can impact confidentiality, integrity, and availability, potentially granting the attacker broad control over a compromised hosting environment.
The CVSS 3.0 vector is as follows: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
This indicates that an attacker must already have a foothold on the server, possibly through a compromised cPanel account, stolen credentials, a vulnerable web application, or another means of local access.
However, the low attack complexity and lack of user interaction make this vulnerability especially concerning in shared hosting and multi-tenant Linux environments.
Affected Products
Acronis has identified the following Linux products as being affected:
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| Acronis Backup plugin for cPanel & WHM | Before build 1.9.3.1021 | Version 1.9.3 HF3 |
| Acronis Backup extension for Plesk | Before build 1.8.11.638 | Version 1.8.11 |
While the company has noted exploitation targeting the Acronis Backup plugin for cPanel & WHM deployments in the wild, it has not observed any exploitation against Plesk environments, despite the underlying privilege escalation issue also affecting its extension.
Administrators should update the Acronis Backup plugin for cPanel & WHM to version 1.9.3 HF3 (build 1.9.3.1021 or later) immediately. Organizations using the Acronis Backup extension for Plesk should upgrade to version 1.8.11 (build 1.8.11.638 or later).
Security teams should also review local accounts, privileged group memberships, scheduled tasks, and recently modified Acronis-related files, and monitor for unusual process activity on servers running the vulnerable software.
Because exploitation requires local access, investigations should focus on signs of an initial compromise, including unauthorized cPanel users, web shell activity, unusual SSH logins, and anomalous administrative commands.
Acronis urges all users to install the update immediately, stressing that the vulnerability is currently being utilized in targeted attacks.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/acronis-backup-plugin-vulnerability/