Junglewise Threat Intelligence

CVE-2026-33271: Acronis True Image local privilege escalation via insecure folder permissions

CVE-2026-33271 · Severity: medium · CVSS 6.7 · Published 2026-04-02

Technologies: Acronis True Image (Windows). Vendors: Acronis.

Executive brief

Acronis True Image is a backup and recovery solution used to protect data on Windows computers. A security flaw in the software's folder permissions could allow a person with limited access to the computer to gain full administrative control. This could lead to unauthorized access to sensitive files, system-wide changes, or the disruption of backup operations.

Technical details

A local privilege escalation vulnerability exists in Acronis True Image for Windows due to incorrect permission assignment for a critical resource (CWE-732). The root cause is insecure folder permissions that allow a low-privileged user to modify files or directories used by the application. An attacker with local access and low privileges can exploit this flaw to execute code with higher privileges, potentially gaining full system access. The exploit requires specific conditions (high complexity) and user interaction. The issue is resolved in Acronis True Image build 42902.

Affected products

  • Acronis True Image (Windows) before build 42902

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats