GBHackers

Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges


Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM on Linux. The company confirmed that attackers have already exploited this flaw in limited, targeted attacks against vulnerable deployments.

This vulnerability is tracked as CVE-2026-87886 and is described as an insecure file permissions issue that could allow a local, low-privileged attacker to gain elevated privileges on the affected Linux server. Acronis has assigned a CVSS score of 7.8 out of 10 to this vulnerability, categorizing it as high severity.

Acronis Backup Plugin Vulnerability

The flaw is detailed in Acronis advisory SEC-10986 and is associated with CWE-276, which refers to incorrect default permissions. Poorly managed file permissions can expose sensitive files, scripts, binaries, or configuration data to users who should not be able to modify or execute them.

According to the CVSS vector, exploitation requires local access and low privileges but no user interaction. Successful exploitation can impact confidentiality, integrity, and availability, potentially granting the attacker broad control over a compromised hosting environment.

The CVSS 3.0 vector is as follows: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

This indicates that an attacker must already have a foothold on the server, possibly through a compromised cPanel account, stolen credentials, a vulnerable web application, or another means of local access.

However, the low attack complexity and lack of user interaction make this vulnerability especially concerning in shared hosting and multi-tenant Linux environments.

Affected Products

Acronis has identified the following Linux products as being affected:

ProductVulnerable VersionsFixed Version
Acronis Backup plugin for cPanel & WHMBefore build 1.9.3.1021Version 1.9.3 HF3
Acronis Backup extension for PleskBefore build 1.8.11.638Version 1.8.11

While the company has noted exploitation targeting the Acronis Backup plugin for cPanel & WHM deployments in the wild, it has not observed any exploitation against Plesk environments, despite the underlying privilege escalation issue also affecting its extension.

Administrators should update the Acronis Backup plugin for cPanel & WHM to version 1.9.3 HF3 (build 1.9.3.1021 or later) immediately. Organizations using the Acronis Backup extension for Plesk should upgrade to version 1.8.11 (build 1.8.11.638 or later).

Security teams should also review local accounts, privileged group memberships, scheduled tasks, and recently modified Acronis-related files, and monitor for unusual process activity on servers running the vulnerable software.

Because exploitation requires local access, investigations should focus on signs of an initial compromise, including unauthorized cPanel users, web shell activity, unusual SSH logins, and anomalous administrative commands.

Acronis urges all users to install the update immediately, stressing that the vulnerability is currently being utilized in targeted attacks.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection



Source link