Particle.news

Acronis Patches High-Severity Privilege Escalation in cPanel and Plesk Backup Plugins

Limited targeted attacks on the cPanel plugin justify Acronis withholding technical details to allow administrators to install urgent fixes

Overview

  • Acronis disclosed CVE-2026-87886, a Linux local privilege escalation rooted in insecure file permissions that lets an authenticated user gain higher privileges without user interaction.
  • The company updated its advisory Tuesday and assigned the flaw a CVSS score of 7.8 while releasing patched builds for affected products.
  • Acronis reported limited, targeted exploitation against the Backup plugin for cPanel & WHM based on a single potentially affected customer report and said it has not published specific indicators of compromise.
  • Administrators should immediately install Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 and Acronis Backup extension for Plesk version 1.8.11 to mitigate the issue.
  • Because these plugins connect hosting control panels to Acronis cloud backups, unchecked privilege escalation could let attackers access hosted sites, mailboxes, databases, and backups, so investigators continue to monitor for wider abuse.