Junglewise Threat Intelligence

CVE-2026-87886: Acronis Backup privilege escalation in cPanel/WHM and Plesk plugins

CVE-2026-87886 · Severity: critical · Exploited in the wild · Published 2026-09-16

Executive brief

Acronis Backup, a widely-used data protection solution, has plugins for popular web hosting control panels (cPanel/WHM and Plesk) that are installed with overly permissive default settings. An attacker with local access to a hosting environment could exploit these incorrect permissions to escalate privileges and gain unauthorized control over backup operations or hosted customer data. This vulnerability is actively being exploited in the wild.

Technical details

The Acronis Backup plugins for cPanel/WHM and Plesk control panels are installed with incorrect default file or directory permissions that fail to properly restrict access. This misconfiguration allows an attacker with local system access (e.g., a compromised hosting account or low-privileged process) to read, modify, or execute protected files, leading to privilege escalation. The vulnerability does not require authentication to the control panel itself, only filesystem-level access. Successful exploitation could grant an attacker elevated privileges to manage backups, access customer data, or compromise the hosting infrastructure. The vulnerability has been observed exploited in active attacks. Patches or configuration updates from Acronis addressing the default permissions are recommended.

Affected products

  • Acronis Backup plugin for cPanel & WHM
  • Acronis Backup extension for Plesk

Timeline

  • 2026-09-16: disclosed: CVE-2026-87886 published
  • exploited: Actively exploited in the wild