Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Acronis has released security updates for its Backup plugin for cPanel & WHM and Backup extension for Plesk after detecting limited, targeted exploitation of a high-severity local privilege-escalation vulnerability in the wild.

Tracked as CVE-2026-87886, the flaw stems from insecure file permissions in the Linux-based Acronis backup components. Acronis assigned the issue a CVSS score of 7.8, rating it as high severity.

The company urged all affected users to install the available fixes immediately. The vulnerability is classified as CWE-276, which refers to incorrect default permissions. Such flaws can expose sensitive files or allow a local account to access resources beyond its intended privilege level.

According to the CVSS vector, an attacker needs local access and low-level privileges to exploit the issue. However, exploitation does not require user interaction.

Successful exploitation could allow an attacker to gain elevated privileges and affect the affected system’s confidentiality, integrity, and availability.

In practical terms, a threat actor who already has access to a vulnerable Linux hosting server, including through a compromised hosting account, weak credentials, a vulnerable web application, or another initial-access method, may be able to abuse the Acronis component to obtain greater permissions.

This could potentially enable access to backup data, system files, hosting control-panel environments, or other customer accounts hosted on the same infrastructure.

Acronis Plugin Vulnerability

Acronis said it has observed exploitation only in limited, targeted attacks. However, public disclosure and patch availability can increase the risk of broader exploitation, as attackers often begin scanning for vulnerable systems after security fixes are released.

The company addressed the vulnerability in the Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3. It also released the Acronis Backup extension for Plesk version 1.8.11 to fix the issue for Plesk environments.

Administrators running either product should verify their installed version and update to the patched release without delay.

Managed service providers and hosting companies should give the issue priority because cPanel and Plesk servers often host multiple websites and customer workloads. A local privilege-escalation flaw in these environments can increase the impact of an initial compromise.

Security teams should also review server activity for signs of unauthorized local access, unexpected privilege changes, suspicious processes running with elevated permissions, and unusual modifications to Acronis-related files or directories.

Reviewing authentication logs, web-shell detections, control-panel account activity, and backup access records may help identify attempted exploitation.

Acronis noted that it does not disclose vulnerability information before patches or releases are generally available. The vendor’s advisory confirms the update fixes one high-severity vulnerability and that exploitation has already been detected in the wild.

Organizations that cannot patch immediately should restrict local access to affected servers, limit shell access for untrusted accounts, closely monitor privileged activity, and, where possible, isolate backup infrastructure from standard hosting workloads.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild appeared first on Cyber Security News.