Skip to content
AcronisCVE-2026-87886

Acronis Backup: privilege escalation

High7.8CVE-2026-87886 · Published Sep 17, 2026 · updated Sep 18, 2026

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Acronis advisory

Affected versions

PackageAffectedFixed in
Acronis Backup extension for Plesk
Product
< 1.8.11.6381.8.11.638
Acronis Backup plugin for DirectAdmin
Product
< 1.2.3.2381.2.3.238
Acronis Backup plugin for cPanel & WHM
Product
< 1.9.3.10211.9.3.1021
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.