Acronis Backup Plugins for cPanel, WHM and Plesk Hit by Privilege Escalation Flaw
A high-severity vulnerability, CVE-2026-87886, has been identified in Acronis Backup plugins for cPanel & WHM and Plesk on Linux systems, caused by insecure file permissions. India's CERT-In published the advisory as CIVN-2026-0466 on 18 September 2026, warning that a remote attacker could exploit the flaw to escalate privileges, execute arbitrary code, or perform unauthorized actions. The affected versions are Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021 and Acronis Backup extension for Plesk before build 1.8.11.638. Because backup plugins handle credentials and data across multiple hosted accounts, a successful attack on a shared hosting node could potentially compromise other tenants on the same machine. Acronis has released fixed builds and advises administrators to upgrade immediately and verify file permissions on plugin directories as per advisory SEC-10986.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in