Local Privilege Escalation Vulnerability in Acronis Backup Products
CVE-2026-87886

7.8HIGH

Key Information:

Badges

📈 Score: 1,850👾 Exploit Exists🦅 CISA Reported📰 News Worthy

What is CVE-2026-87886?

CVE-2026-87886 is a local privilege escalation vulnerability found in specific Acronis Backup products designed for data protection and recovery solutions. Acronis software assists organizations in backing up and restoring their data, ensuring business continuity and data integrity. This vulnerability arises due to insecure file permissions within the affected products, which include the Acronis Backup plugin for cPanel & WHM (Linux) prior to build 1.9.3.1021, the Acronis Backup extension for Plesk (Linux) prior to build 1.8.11.638, and the Acronis Backup plugin for DirectAdmin (Linux) prior to build 1.2.4.238. If exploited, the vulnerability could allow an authenticated user to elevate their privileges, potentially granting them unauthorized access to sensitive data and system resources.

Potential impact of CVE-2026-87886

  1. Unauthorized Access: The primary impact of this vulnerability is the risk of unauthorized access to sensitive files and system settings. Attackers could leverage this privilege escalation to manipulate or exfiltrate critical organizational data, leading to significant data breaches.

  2. System Compromise: By exploiting CVE-2026-87886, attackers can gain elevated privileges that allow them to execute arbitrary commands on the system, compromising its integrity and availability. This could result in the installation of malware or ransomware, posing additional risks to the organization.

  3. Business Disruption: The exploitation of this vulnerability can cause major disruptions to organizational operations. By potentially enabling malicious actors to disrupt backup services or delete crucial data, it can hamper recovery efforts during critical incidents, putting the organization at risk of extended downtime and financial loss.

CISA has reported CVE-2026-87886

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-87886 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Acronis Backup extension for Plesk Linux < 1.8.11.638

Acronis Backup plugin for cPanel & WHM Linux < 1.9.3.1021

Acronis Backup plugin for DirectAdmin Linux < 1.2.3.238

News Articles

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far

3 weeks ago

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis says CVE-2026-87886, a local privilege escalation flaw in its Linux backup plugins, was exploited in limited targeted attacks.

4 weeks ago

Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) - IT Security News

2026-09-16 12:09 A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by...

4 weeks ago

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability Reserved

.