Credential Management Flaw in Acronis Cyber Protect Software Suite
CVE-2025-30413
4.4MEDIUM
Key Information:
- Vendor
Acronis
- Vendor
- CVE Published:
- 5 March 2026
What is CVE-2025-30413?
Acronis Cyber Protect products exhibit a significant security concern concerning credential management. After the revocation of a backup plan, the software fails to adequately delete user credentials from the Acronis Agent across multiple operating systems, including Linux, macOS, and Windows. This issue potentially exposes sensitive user information, creating risks for unauthorized access and compromised system integrity. Users of the affected versions should ensure they update to the latest builds to mitigate this vulnerability.
Affected Version(s)
Acronis Cyber Protect 17 Linux < 41186
Acronis Cyber Protect Cloud Agent Linux < 40497
References
CVSS V3.0
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Airbus SecLab (mailto:vuln@airbus.com)
Quentin Liddell (mailto:vuln@airbus.com)
Mattéo Ricordeau (mailto:vuln@airbus.com)
Benoît Camredon (mailto:vuln@airbus.com)