Critical Acronis Cyber Protection Vulnerability in cPanel, Plesk Exploosed
Key Takeaways Acronis has issued critical security updates for its backup plugins used with cPanel & WHM and Plesk. A high-severity local privilege escalation vulnerability (CVE-2026-87886) has...
Key Takeaways
- Acronis has issued critical security updates for its backup plugins used with cPanel & WHM and Plesk.
- A high-severity local privilege escalation vulnerability (CVE-2026-87886) has been identified and is being actively exploited in targeted attacks.
- The flaw, rated 7.8 CVSS, stems from insecure file permissions in Linux-based Acronis components.
- Patches are available in Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 and Acronis Backup extension for Plesk version 1.8.11.
- Immediate updates are strongly recommended for all affected users, especially managed service providers and hosting companies.
Acronis Patches Critical Privilege Escalation Flaw Under Active Exploitation
Acronis has released urgent security updates for its backup solutions integrated with cPanel & WHM and Plesk, responding to evidence of limited, targeted exploitation of a critical local privilege escalation vulnerability. The flaw, designated CVE-2026-87886, affects Linux-based components and has been assigned a CVSS score of 7.8, indicating high severity.
Table Of Content
The vulnerability arises from insecure default file permissions within the Acronis backup software, categorized as CWE-276. This type of weakness can allow a local attacker to bypass intended security controls, gaining unauthorized access to sensitive data or elevating their privileges beyond what is permitted.
According to the CVSS vector, an attacker requires pre-existing local access and low-level privileges to exploit this flaw, though no user interaction is necessary for successful execution. Exploitation could lead to an attacker acquiring elevated system permissions, thereby compromising the confidentiality, integrity, and availability of the affected system.
In practical terms, a threat actor who has already secured a foothold on a vulnerable Linux hosting server—perhaps through a compromised user account, weak credentials, a vulnerable web application, or another initial access vector—could leverage this Acronis component to escalate their privileges. Such an escalation could potentially grant access to critical backup data, core system files, administrative areas of hosting control panels, or even other customer accounts residing on the same infrastructure.
Addressing the Acronis Plugin Vulnerability
Acronis said that while exploitation has so far been observed in only limited, targeted attacks, the public disclosure of the vulnerability and the availability of patches typically increase the risk of broader exploitation. Cybercriminals often initiate widespread scanning for vulnerable systems once security fixes become public knowledge.
The company has addressed the vulnerability in Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3. For Plesk environments, the fix is included in Acronis Backup extension for Plesk version 1.8.11. Administrators of either product should verify their current installed versions and apply the respective patched releases without delay.
This issue warrants high priority for managed service providers and hosting companies. Given that cPanel and Plesk servers frequently host multiple websites and diverse customer workloads, a local privilege escalation flaw in these environments can significantly amplify the impact of an initial compromise, potentially affecting numerous clients.
Security teams should also conduct thorough reviews of server activity for any indicators of unauthorized local access, unexpected changes in user privileges, suspicious processes running with elevated permissions, or unusual modifications to Acronis-related files or directories. Examining authentication logs, web shell detections, control panel account activity, and backup access records can aid in identifying attempted exploitation. The vendor’s advisory confirms the update specifically addresses one high-severity vulnerability and that exploitation has been detected in the wild. Acronis maintains a policy of not disclosing vulnerability details until patches are generally available.
What You Should Do
- Update Immediately: Apply the latest security updates for Acronis Backup plugin for cPanel & WHM (version 1.9.3 HF3) and Acronis Backup extension for Plesk (version 1.8.11).
- Monitor Server Activity: Actively look for signs of unauthorized local access, unusual privilege changes, suspicious processes, or modifications to Acronis files.
- Review Logs: Scrutinize authentication logs, web shell detections, control panel account activity, and backup access records for any anomalies.
- Restrict Local Access: If immediate patching is not possible, restrict local access to affected servers and limit shell access for untrusted accounts.
- Isolate Infrastructure: Where feasible, isolate backup infrastructure from standard hosting workloads to minimize potential impact.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.