AcronisCVE-2026-87886
Acronis Backup: privilege escalation
High7.8CVE-2026-87886 · Published Sep 17, 2026 · updated Sep 18, 2026
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Acronis Backup extension for Plesk Product | < 1.8.11.638 | 1.8.11.638 |
| Acronis Backup plugin for DirectAdmin Product | < 1.2.3.238 | 1.2.3.238 |
| Acronis Backup plugin for cPanel & WHM Product | < 1.9.3.1021 | 1.9.3.1021 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-276