Local Privilege Escalation Vulnerability in Acronis Backup Products
CVE-2026-87886
Key Information:
- Vendor
Acronis
- Status
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-87886?
CVE-2026-87886 is a local privilege escalation vulnerability found in specific Acronis Backup products designed for data protection and recovery solutions. Acronis software assists organizations in backing up and restoring their data, ensuring business continuity and data integrity. This vulnerability arises due to insecure file permissions within the affected products, which include the Acronis Backup plugin for cPanel & WHM (Linux) prior to build 1.9.3.1021, the Acronis Backup extension for Plesk (Linux) prior to build 1.8.11.638, and the Acronis Backup plugin for DirectAdmin (Linux) prior to build 1.2.4.238. If exploited, the vulnerability could allow an authenticated user to elevate their privileges, potentially granting them unauthorized access to sensitive data and system resources.
Potential impact of CVE-2026-87886
-
Unauthorized Access: The primary impact of this vulnerability is the risk of unauthorized access to sensitive files and system settings. Attackers could leverage this privilege escalation to manipulate or exfiltrate critical organizational data, leading to significant data breaches.
-
System Compromise: By exploiting CVE-2026-87886, attackers can gain elevated privileges that allow them to execute arbitrary commands on the system, compromising its integrity and availability. This could result in the installation of malware or ransomware, posing additional risks to the organization.
-
Business Disruption: The exploitation of this vulnerability can cause major disruptions to organizational operations. By potentially enabling malicious actors to disrupt backup services or delete crucial data, it can hamper recovery efforts during critical incidents, putting the organization at risk of extended downtime and financial loss.
CISA has reported CVE-2026-87886
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-87886 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Acronis Backup extension for Plesk Linux < 1.8.11.638
Acronis Backup plugin for cPanel & WHM Linux < 1.9.3.1021
Acronis Backup plugin for DirectAdmin Linux < 1.2.3.238
News Articles
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far
3 weeks ago
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis says CVE-2026-87886, a local privilege escalation flaw in its Linux backup plugins, was exploited in limited targeted attacks.
4 weeks ago
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) - IT Security News
2026-09-16 12:09 A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by...
4 weeks ago
References
CVSS V3.0
Timeline
Vulnerability published
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by BleepingComputer
Vulnerability Reserved