Junglewise Threat Intelligence

CVE-2026-27774: Acronis True Image DLL hijacking privilege escalation

CVE-2026-27774 · Severity: medium · CVSS 6.7 · Published 2026-04-02

Technologies: Acronis True Image (Windows). Vendors: Acronis.

Executive brief

Acronis True Image, a popular backup and data protection software, is vulnerable to a security flaw that could allow a local user to gain higher system permissions. By placing a malicious file in a specific location on the computer, an attacker could trick the software into running unauthorized code. This could lead to a full takeover of the affected Windows machine, potentially compromising sensitive backups and system integrity.

Technical details

A DLL hijacking vulnerability (CWE-427: Uncontrolled Search Path Element) exists in Acronis True Image for Windows before build 42902. The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs), allowing a local attacker with low privileges to place a malicious DLL in a directory searched by the application. If a user with higher privileges or a system process executes the application, the malicious DLL is loaded and executed with those elevated permissions. Exploitation requires local access and some level of user interaction or specific environmental conditions (high complexity). A fix is available in build 42902 and later.

Affected products

  • Acronis True Image (Windows) before build 42902

Timeline

  • 2026-04-02: disclosed: Initial advisory publication
  • 2026-04-02: advisory: NVD entry created

References

Related threats