7.8

CVE-2026-87886

Warnung
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Acronis ≫ Acronis Backup SwPlatform directadmin Version < 1.2.3
   Linux ≫ Linux Kernel Version -
Acronis ≫ Acronis Backup SwPlatform plesk Version < 1.8.11
   Linux ≫ Linux Kernel Version -
Acronis ≫ Acronis Backup SwPlatform cpanel Version < 1.9.3
   Linux ≫ Linux Kernel Version -
Acronis ≫ Acronis Backup Version 1.9.3 Update - SwPlatform cpanel
   Linux ≫ Linux Kernel Version -
Acronis ≫ Acronis Backup Version 1.9.3 Update hotfix1 SwPlatform cpanel
   Linux ≫ Linux Kernel Version -
Acronis ≫ Acronis Backup Version 1.9.3 Update hotfix2 SwPlatform cpanel
   Linux ≫ Linux Kernel Version -

16.09.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Acronis Backup Incorrect Default Permissions Vulnerability

Schwachstelle

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.174
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@acronis.com 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://security-advisory.acronis.com/advisories/SEC-10986
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87886
US Government Resource