Vulnerability Management

Acronis backup plugin vulnerability allows privilege escalation

As reported by Bleeping Computer, a critical vulnerability has been disclosed in Acronis' backup plugin for cPanel, WebHost Manager (WHM), and Plesk, potentially allowing attackers to escalate privileges on affected Linux servers.

Acronis has identified CVE-2026-87886, a high-severity local privilege escalation flaw, in its backup add-ons for popular web hosting control panels. This vulnerability, rated 7.8, allows a low-privileged attacker to gain higher permission levels on a Linux server. While Acronis has not released extensive technical details to allow administrators time to patch, they have confirmed limited, targeted exploitation in the wild. The affected versions include Acronis Backup plugin for cPanel & WHM builds prior to 1.9.3.1021 and Acronis Backup extension for Plesk builds before 1.8.11.638.

Administrators using these Acronis backup integrations are strongly advised to update to the patched versions immediately to mitigate the risk of unauthorized access and potential system disruption.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds