Cyber Security News

Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges

Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM on Linux. The company confirmed that attackers have already exploited this flaw in limited, targeted attacks against vulnerable deployments.

This vulnerability is tracked as CVE-2026-87886 and is described as an insecure file permissions issue that could allow a local, low-privileged attacker to gain elevated privileges on the affected Linux server. Acronis has assigned a CVSS score of 7.8 out of 10 to this vulnerability, categorizing it as high severity.

Acronis Backup Plugin Vulnerability

The flaw is detailed in Acronis advisory SEC-10986 and is associated with CWE-276, which refers to incorrect default permissions. Poorly managed file permissions can expose sensitive files, scripts, binaries, or configuration data to users who should not be able to modify or execute them.

According to the CVSS vector, exploitation requires local access and low privileges but no user interaction. Successful exploitation can impact confidentiality, integrity, and availability, potentially granting the attacker broad control over a compromised hosting environment.

The CVSS 3.0 vector is as follows: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

This indicates that an attacker must already have a foothold on the server, possibly through a compromised cPanel account, stolen credentials, a vulnerable web application, or another means of local access.

However, the low attack complexity and lack of user interaction make this vulnerability especially concerning in shared hosting and multi-tenant Linux environments.

Affected Products

Acronis has identified the following Linux products as being affected:

ProductVulnerable VersionsFixed Version
Acronis Backup plugin for cPanel & WHMBefore build 1.9.3.1021Version 1.9.3 HF3
Acronis Backup extension for PleskBefore build 1.8.11.638Version 1.8.11

While the company has noted exploitation targeting the Acronis Backup plugin for cPanel & WHM deployments in the wild, it has not observed any exploitation against Plesk environments, despite the underlying privilege escalation issue also affecting its extension.

Administrators should update the Acronis Backup plugin for cPanel & WHM to version 1.9.3 HF3 (build 1.9.3.1021 or later) immediately. Organizations using the Acronis Backup extension for Plesk should upgrade to version 1.8.11 (build 1.8.11.638 or later).

Security teams should also review local accounts, privileged group memberships, scheduled tasks, and recently modified Acronis-related files, and monitor for unusual process activity on servers running the vulnerable software.

Because exploitation requires local access, investigations should focus on signs of an initial compromise, including unauthorized cPanel users, web shell activity, unusual SSH logins, and anomalous administrative commands.

Acronis urges all users to install the update immediately, stressing that the vulnerability is currently being utilized in targeted attacks.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

5 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

5 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

6 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

7 hours ago