Executive brief
Acronis Backup, a widely-used data protection solution, has plugins for popular web hosting control panels (cPanel/WHM and Plesk) that are installed with overly permissive default settings. An attacker with local access to a hosting environment could exploit these incorrect permissions to escalate privileges and gain unauthorized control over backup operations or hosted customer data. This vulnerability is actively being exploited in the wild.
Technical details
The Acronis Backup plugins for cPanel/WHM and Plesk control panels are installed with incorrect default file or directory permissions that fail to properly restrict access. This misconfiguration allows an attacker with local system access (e.g., a compromised hosting account or low-privileged process) to read, modify, or execute protected files, leading to privilege escalation. The vulnerability does not require authentication to the control panel itself, only filesystem-level access. Successful exploitation could grant an attacker elevated privileges to manage backups, access customer data, or compromise the hosting infrastructure. The vulnerability has been observed exploited in active attacks. Patches or configuration updates from Acronis addressing the default permissions are recommended.
Affected products
- Acronis Backup plugin for cPanel & WHM
- Acronis Backup extension for Plesk
Timeline
- 2026-09-16: disclosed: CVE-2026-87886 published
- exploited: Actively exploited in the wild