Junglewise Threat Intelligence

CVE-2026-41952: Acronis Windows Agents local privilege escalation via improper input validation

CVE-2026-41952 · Severity: high · CVSS 7.8 · Published 2026-04-29

Technologies: Acronis DeviceLock DLP. Vendors: Acronis.

Executive brief

Acronis security and data loss prevention agents for Windows are affected by a vulnerability that allows a user with low-level access to gain full administrative control over the system. This could allow an attacker to bypass security policies, access sensitive data, or disable protection software. Organizations should update their Acronis agents to the latest builds to prevent local users from escalating their privileges.

Technical details

A local privilege escalation vulnerability exists in Acronis DeviceLock DLP and Cyber Protect Cloud Agent for Windows due to improper input validation, specifically a 'write-what-where' condition (CWE-123). An attacker with low-privileged local access can exploit this flaw to overwrite sensitive memory or system files, leading to the execution of arbitrary code with SYSTEM-level privileges. The vulnerability is addressed in DeviceLock DLP build 9.0.93212 and Cyber Protect Cloud Agent build 42183. Exploitation does not require user interaction or complex configurations.

Affected products

  • Acronis DeviceLock DLP (Windows) before build 9.0.93212
  • Acronis Cyber Protect Cloud Agent (Windows) before build 42183

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: advisory

References

Related threats