[CIVN-2026-0465] Privilege Escalation Vulnerability in Acronis cPanel Backup Plugin

By Published On: September 18, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Privilege Escalation Vulnerability in Acronis cPanel Backup Plugin


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021

Acronis Backup extension for Plesk (Linux) before build 1.8.11.638

Overview


A vulnerability has been reported in Acronis Backup plugins for cPanel, WHM, and Plesk which could allow a remote attacker to gain elevated privileges on the targeted system.


Target Audience:

System administrators using the affected Acronis Backup plugins.


Risk Assessment:

High risk of privilege escalation.


Impact Assessment:

Potential for unauthorized actions or execution of arbitrary code.


Description


Acronis Backup Plugin for cPanel is a software extension that integrates Acroniss enterprise cloud backup features directly into the cPanel & WHM (Web Host Manager) control panel.


This vulnerability exist in Acronis Backup plugins for cPanel, WHM, and Plesk due to insecure file permissions. A remote attacker could exploit this vulnerability by gaining access to the targeted system.


Successful exploitation of this vulnerability could allow an attacker to elevate privileges, execute arbitrary code, or perform unauthorized actions on the targeted system.


Solution


Apply the latest security updates provided by the vendor:

https://security-advisory.acronis.com/advisories/SEC-10986



Vendor Information


Acronis

https://www.acronis.com


References


 

https://security-advisory.acronis.com/advisories/SEC-10986


CVE Name

CVE-2026-87886




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: [email protected]

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtUtAACgkQ3jCgcSdc

ys9YQQ/8Dl62/lmswj6vFqvRwqa9mnz/YJSEmKi27zLgvMzZOE2B2jq1bVVEbIWs

CNdYx5fyK+TJZ/dy4jNYHA6pvfN/mdvlZvz90xFxoEiF/+//4WfIMM+742dPMZwl

uHBbukxAY/DgNHSJ+hPqil/YnDFHm7b457Rop05ZHmLALg6vRSo0sx5uGofwPvN2

fuZgSmYGfY6NSbx90lbch8O0GuzomvtEc8xoR9znorKlfKPfbfbK44lHXYGxpkux

0Ei/fUpPWUuPHN8RBLTkxL9oFc2zFMoPSe5aZ14OolemdOnnCSh0bOP9yDPavA+S

UwR85s/UJP52KURMLjKZYA+fsnhTqO99vHEp3+JQfia7WzVWLg0Vylzs0HYTP3m1

ITDjN57r7jnnoIGhiEK9H3QFq4fdGg1gAunISH3NioVD1pERZjBEr9hvd30GENx6

fLaiaz9QR4i8JdPLyJJUbpE6xUvOaxbzJnsgN4ynOQqnyK1AKg7+Fy3m9ix/Yeit

SkFAcTeNiwCkfwGgL8Xh0Ij6CUfMK7ZNc5H3blz+AuMNJi85O8s2s1muJd0Dsz8S

Z7Z3W6e2m2sQWAMBr5fbrR4fVN7YHeQdqkoHMfqjOgwnmH5TJ5VS3PyMuJb4ZyLl

KCkQSUxTQeKwO66iRFC+TeinL0AtIFj8C2Tb9BYvev9z/og6x5Q=

=zWlZ

—–END PGP SIGNATURE—–

Share this article