Acronis Backup Plugin Flaw CVE-2026-87886 Exploited in Targeted Attacks

www.news4hackers.com-acronis-backup-plugin-flaw-cve-2026-87886-exploited-in-targeted-attacks-acronis-backup-plugin-flaw-cve-2026-87886-exploited-in-targeted-attacks

A critical security vulnerability (CVE-2026-87886) in Acronis backup extensions for cPanel, WebHost Manager (WHM), and Plesk has been actively exploited in limited, targeted campaigns, according to the company’s security advisory issued on Tuesday.

Vulnerability Overview

The flaw, which enables local privilege escalation on Linux systems, has been observed in attacks against Acronis Backup plugins deployed on cPanel WHM environments. No evidence of exploitation has been reported for Plesk-based systems.

Plugin Functionality

The Acronis backup plugins integrate cPanel WHM and Plesk control panels with the company’s cloud infrastructure, allowing administrators to manage server backups, website data, and email archives through a centralized interface. These tools are widely used by managed service providers and web hosting companies to deliver backup solutions under their own branding.

Vulnerability Details

The vulnerability arises from improper file permission configurations, enabling authenticated users to escalate privileges without user interaction. The Common Vulnerability Scoring System (CVSS) rating indicates the flaw can be exploited with low complexity, requiring minimal prerequisites for successful attack execution.

Patches and Recommendations

Despite the release of security patches for affected plugins last week, Acronis has not disclosed specifics about the methods employed by threat actors during in-the-wild attacks. Administrators are urged to apply the following updates immediately:

  • Acronis Backup plugin for cPanel WHM version 1.9.3 HF3
  • Acronis Backup extension for Plesk version 1.8.11

Post-Exploitation Concerns

The company has not provided details on the scope of the attacks, including the nature of post-exploitation activities or the potential impact on compromised systems. Organizations using the affected plugins are advised to review their server configurations, verify patch compliance, and monitor for signs of unauthorized access.

Conclusion

The incident highlights the risks associated with misconfigured permissions in third-party software integrations and underscores the importance of timely vulnerability remediation in managed hosting environments.



About Author

en_USEnglish