Privilege Escalation Vulnerability in Acronis Backup for cPanel and Plesk
Acronis Backup for cPanel and WHM and the extension for Plesk contain an incorrect default permissions vulnerability (CVE-2026-87886) that enables privilege escalation.
Acronis Backup for cPanel and WHM, as well as the Acronis extension for Plesk, are affected by an incorrect default permissions vulnerability identified as CVE-2026-87886. This flaw exists within the plugin's file or directory permission structure, which is improperly configured during installation or runtime. An attacker with limited access to the server environment where these panels reside could leverage these insecure permissions to perform unauthorized actions, effectively escalating their privileges to the context of the backup service or the panel itself. Given the elevated nature of these administrative interfaces, this vulnerability poses a significant risk to the integrity and confidentiality of backed-up data and the underlying server infrastructure. Defenders are required to prioritize patching in accordance with CISA Binding Operational Directive (BOD) 26-04.
Impact
Successful exploitation of CVE-2026-87886 allows local unprivileged users to escalate privileges, potentially leading to unauthorized data access, modification of backup configurations, or full control over the cPanel or Plesk management interfaces. This affects organizations utilizing Acronis Backup plugins in shared hosting or enterprise management environments. Impacted systems are subject to strict remediation timelines under CISA BOD 26-04 to prevent potential lateral movement and data exfiltration.
Recommendation
Prioritize the immediate application of vendor-supplied patches for Acronis Backup plugins in accordance with CISA BOD 26-04. Verify the integrity of file permissions for the Acronis plugin directories post-patching. If patches are unavailable, evaluate the business necessity of the plugin and consider disabling the extension until remediation is confirmed. Consult the vendor security advisory at https://security-advisory.acronis.com/advisories/SEC-10986 for specific version requirements.
Immediate actions
Patch Acronis Backup plugins to the version specified in the vendor advisory SEC-10986.
Mitigations
Review server permissions for Acronis plugin directories for deviations from principle of least privilege.
CVE-2026-87886