Local Privilege Escalation in Acronis Cyber Protect 17 by Acronis
CVE-2026-28712

6.3MEDIUM

Key Information:

Vendor

Acronis

Vendor
CVE Published:
5 March 2026

What is CVE-2026-28712?

Acronis Cyber Protect 17 for Windows is vulnerable to a local privilege escalation due to a DLL hijacking issue. This can allow an attacker to execute arbitrary code with the privileges of another user, potentially leading to unauthorized access and control over the system. Users are encouraged to update to build 41186 or later to mitigate this risk.

Affected Version(s)

Acronis Cyber Protect 17 Windows < 41186

References

CVSS V3.0

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@vanitas (https://hackerone.com/vanitas)
.