Acronis Backup Incorrect Default Permissions Vulnerability

🚨SEVERITY: UNKNOWNSecurity Advisory

TL;DR 📌

  • Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
  • Listed in CISA KEV (2026-09-16) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-87886.

What it is

CVE-2026-87886 affects the Acronis Backup plugin for cPanel & WHM and the equivalent extension for Plesk. The flaw is an incorrect default permissions issue, which typically means files, directories, or configuration data tied to the plugin are left accessible in a way that allows a local user without the intended privilege level to read, modify, or otherwise interact with them.

Acronis describes the impact as privilege escalation. In the context of a cPanel/WHM or Plesk host, this points to a local attacker — someone who already has an account or shell access on the server, such as a hosting customer — using the misconfigured permissions to gain rights beyond their own account, potentially reaching root or the panel’s administrative context.

The advisory does not specify the exact files, paths, or permission bits involved, nor does it give a CVSS score. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-09-16, so it is known to be exploited.

What to do

  • Identify all hosts running the Acronis Backup plugin for cPanel & WHM or the Acronis Backup extension for Plesk.
  • Consult the Acronis advisory for CVE-2026-87886 directly, as no fixed version is stated here — check for an updated plugin/extension release and apply it as soon as it’s available.
  • Given the KEV listing, treat this as a priority patching item; do not wait for a routine maintenance window.
  • Where patching isn’t immediately possible, review file and directory permissions associated with the Acronis Backup plugin/extension on affected hosts and tighten any that are unnecessarily world- or group-writable.
  • Restrict local shell and panel access on multi-tenant hosts (shared hosting, reseller accounts) until the fix is confirmed applied, since the escalation path relies on existing local access.
  • Monitor for unexpected privilege changes or new administrative accounts on cPanel/WHM and Plesk servers as part of routine log review.

For leadership 🧭

Executive summary. On any cPanel/WHM or Plesk host running the Acronis Backup plugin, a customer or other local account could exploit weak default permissions to gain root or panel-admin rights. This is already listed in CISA’s Known Exploited Vulnerabilities catalogue, so treat it as an active, urgent risk rather than a theoretical one.

Why it matters:

  • The flaw sits in the Acronis Backup plugin for cPanel & WHM and the equivalent Plesk extension, both common on multi-tenant hosting platforms where many unrelated customers share a server.
  • Incorrect default permissions mean a local user with only their own hosting account or shell access could read or modify plugin files and reach root or the panel’s administrative context.
  • CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation, which raises the urgency for any shared hosting environment running the plugin.
  • No CVSS score or fixed version is published, so exposure and remediation timelines must be assessed directly against each host’s plugin/extension version.

Now / Next / Later:

  • Now: Inventory every cPanel/WHM and Plesk host running the Acronis Backup plugin or extension and check the Acronis advisory for CVE-2026-87886 for an available update.
  • Next: Apply the fixed plugin or extension release as soon as Acronis publishes one, prioritising shared or reseller hosting hosts where multiple local accounts exist.
  • Later: Where a fix isn’t yet available, tighten file and directory permissions tied to the plugin, restrict local shell and panel access on multi-tenant boxes, and review logs for unexpected privilege changes or new admin accounts.

Source