Overview
- Acronis assigned CVE-2026-87886 to a high-severity Linux local privilege-escalation bug that stems from insecure file permissions in its Backup plugins for cPanel/WHM and Plesk.
- The company released fixes for affected builds and told users to install cPanel plugin 1.9.3 HF3 and Plesk extension 1.8.11 without delay.
- Acronis says it detected limited, targeted exploitation in the wild against the cPanel/WHM plugin based on a single potentially affected customer report and has not confirmed broader compromise.
- The vendor has not published technical exploit details or indicators of compromise, citing the need to give administrators time to patch before releasing more information.
- If left unpatched, the flaw lets a low-privileged, authenticated user on a Linux server elevate privileges which could allow access to backups, modification of data, or disruption of hosting services and raise risks for hosting providers and their customers.