{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/backup-for-cpanel-and-whm/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:acronis:backup:*:*:*:*:*:cpanel:*:*","cpe:2.3:a:acronis:backup:*:*:*:*:*:plesk:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Backup (for cPanel and WHM)","Backup (extension for Plesk)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","server-security"],"_cs_type":"advisory","_cs_vendors":["Acronis"],"content_html":"\u003cp\u003eAcronis Backup for cPanel and WHM, as well as the Acronis extension for Plesk, are affected by an incorrect default permissions vulnerability identified as CVE-2026-87886. This flaw exists within the plugin's file or directory permission structure, which is improperly configured during installation or runtime. An attacker with limited access to the server environment where these panels reside could leverage these insecure permissions to perform unauthorized actions, effectively escalating their privileges to the context of the backup service or the panel itself. Given the elevated nature of these administrative interfaces, this vulnerability poses a significant risk to the integrity and confidentiality of backed-up data and the underlying server infrastructure. Defenders are required to prioritize patching in accordance with CISA Binding Operational Directive (BOD) 26-04.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-87886 allows local unprivileged users to escalate privileges, potentially leading to unauthorized data access, modification of backup configurations, or full control over the cPanel or Plesk management interfaces. This affects organizations utilizing Acronis Backup plugins in shared hosting or enterprise management environments. Impacted systems are subject to strict remediation timelines under CISA BOD 26-04 to prevent potential lateral movement and data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate application of vendor-supplied patches for Acronis Backup plugins in accordance with CISA BOD 26-04. Verify the integrity of file permissions for the Acronis plugin directories post-patching. If patches are unavailable, evaluate the business necessity of the plugin and consider disabling the extension until remediation is confirmed. Consult the vendor security advisory at \u003ca href=\"https://security-advisory.acronis.com/advisories/SEC-10986\"\u003ehttps://security-advisory.acronis.com/advisories/SEC-10986\u003c/a\u003e for specific version requirements.\u003c/p\u003e\n","date_modified":"2026-09-17T00:59:38Z","date_published":"2026-09-17T00:59:38Z","id":"https://feed.craftedsignal.io/briefs/2026-09-acronis-privesc/","summary":"Acronis Backup for cPanel and WHM and the extension for Plesk contain an incorrect default permissions vulnerability (CVE-2026-87886) that enables privilege escalation.","title":"Privilege Escalation Vulnerability in Acronis Backup for cPanel and Plesk","url":"https://feed.craftedsignal.io/briefs/2026-09-acronis-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Backup (For CPanel and WHM)","version":"https://jsonfeed.org/version/1.1"}