[CIVN-2026-0466] Privilege Escalation Vulnerability in Acronis cPanel Backup Plugin

By Published On: September 18, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Privilege Escalation Vulnerability in Acronis cPanel Backup Plugin


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021

Acronis Backup extension for Plesk (Linux) before build 1.8.11.638

Overview


A vulnerability has been reported in Acronis Backup plugins for cPanel, WHM, and Plesk which could allow a remote attacker to gain elevated privileges on the targeted system.


Target Audience:

System administrators using the affected Acronis Backup plugins.


Risk Assessment:

High risk of privilege escalation.


Impact Assessment:

Potential for unauthorized actions or execution of arbitrary code.


Description


Acronis Backup Plugin for cPanel is a software extension that integrates Acroniss enterprise cloud backup features directly into the cPanel & WHM (Web Host Manager) control panel.


This vulnerability exist in Acronis Backup plugins for cPanel, WHM, and Plesk due to insecure file permissions. A remote attacker could exploit this vulnerability by gaining access to the targeted system.


Successful exploitation of this vulnerability could allow an attacker to elevate privileges, execute arbitrary code, or perform unauthorized actions on the targeted system.


Solution


Apply the latest security updates provided by the vendor:

https://security-advisory.acronis.com/advisories/SEC-10986



Vendor Information


Acronis

https://www.acronis.com


References


 

https://security-advisory.acronis.com/advisories/SEC-10986


CVE Name

CVE-2026-87886




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtVQYACgkQ3jCgcSdc

ys8+8g//Sv8bhTnd2zUkpsHpOofbiSx0MAcU+kgJ05RPFXcwZjTynlR9toCo7Mzf

xnwCIiMc1kVkgX+QRHta+wUiPnAr0ZFEDZQl4kQWVhX+aJ85fuB4p78afq1vUrOe

6sGiYGC9Xb3yA7Gpn0n4/oNjmxEHPBbEooBb7t7QKb7OTSqDz6tN16PH+wybU1YH

1JYhZXhlVOd7hzhk94rdN/J4+493Lhc5FChXTVLQfG9Y8zMOv7NHwIuFk4ncGvEC

NpC6Gp/3WGiRDEI0VDuu0gSvaXOvXNtPIYeiCkz+LoInJCGaXECTz0JkSgdCGlxB

IZa7xABtD9qrNHCXLPVndT8feJQwjh0NqN3H6rQRoCb/MAU/tZIdr7LgyhrerM5o

bOruJG72WjJDKNwZRMi1HXhcyNFwYguq2U7MzvRaoXSJJMe+QTmDY45jxyBqrrXe

Rcj6io8gJMH1zV+e/A91dgaTGgHlIQJe094gs3i8qSwVQr2hWfh+O6FpqEh/zge6

TiEiPj9zyQMd009md/seOy9CTlPXJT7QYLk5g+Q5v3FnWaUS6Y6b7c36UhPv/QzB

DY8dLnbjtKJN/IOAzyyzxU7mWO9CKn/2HBeX4++KEpzIUjKDR4bv0LzGqFWMfFnJ

1Quw6gJam7hHtxn3EbGrlIXwZEEqg+kAreWTZGJ8WgZWM8XgKDQ=

=BSDL

—–END PGP SIGNATURE—–

Share this article