Local Privilege Escalation in Acronis Cyber Protect Cloud Agent
CVE-2025-48963

7.3HIGH

Key Information:

Vendor

Acronis

Vendor
CVE Published:
28 August 2025

What is CVE-2025-48963?

Acronis Cyber Protect Cloud Agent is vulnerable due to improper handling of soft links, which could allow a local attacker to escalate privileges on the system. This issue affects the software across Linux, macOS, and Windows platforms prior to build 40296, potentially enabling unauthorized access to sensitive system resources and compromising the integrity of the affected systems.

Affected Version(s)

Acronis Cyber Protect Cloud Agent Linux < 40296

References

CVSS V3.0

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@vultza (https://hackerone.com/vultza)
.
CVE-2025-48963 : Local Privilege Escalation in Acronis Cyber Protect Cloud Agent