CVE-2026-87886 — Acronis Backup Incorrect Default Permissions Vulnerability

CVE-2026-87886

Acronis Backup for cPanel/Plesk - Insecure Permissions Local Privilege Escalation

What is the Acronis Backup plugin?

The Acronis Backup plugin for cPanel & WHM and the corresponding extension for Plesk integrate Acronis backup functionality directly into the two dominant web-hosting control panels. They run on Linux hosting servers, often shared servers carrying many tenant accounts. Hosting-control-panel plugins are high-value targets: a single flaw in a component that runs with elevated rights can expose or compromise every tenant on the machine, so a local privilege-escalation bug here has outsized reach.

Overview

CVE-2026-87886 is an incorrect default permissions vulnerability (CWE-276) in the Acronis Backup plugin for cPanel & WHM and the extension for Plesk. Insecure file permissions in the Linux backup components let a local, low-privileged attacker escalate privileges on the host. Acronis assigned a CVSS score of 7.8 (high). There was no NVD record at the time of the KEV listing on 2026-09-16, and CISA added the CVE the same day Acronis published advisory SEC-10986.

Affected Versions

Product Affected Fixed
Acronis Backup plugin for cPanel & WHM (Linux) Builds before 1.9.3.1021 1.9.3 HF3
Acronis Backup extension for Plesk (Linux) Builds before 1.8.11.638 1.8.11

Update the cPanel & WHM plugin to 1.9.3 HF3 or later and the Plesk extension to 1.8.11 or later. Consult SEC-10986 for the authoritative build numbers.

Technical Details

Incorrect default permissions (CWE-276) means the software installs files or directories with permissions more permissive than they should be. In this case the Acronis backup components on Linux are created with insecure permissions that a local, low-privileged user can abuse to gain higher privileges on the host, with no user interaction required.

Attack characteristics:

  • Authentication: local, low-privileged account required
  • User interaction: none
  • Vector: local
  • Impact: privilege escalation on the hosting server

Because the flaw is local, it is a second-stage bug: it matters most on multi-tenant hosting servers where an attacker already controls one low-privileged account, such as a single cPanel user, and uses the weak permissions to escalate toward root and reach other tenants.

Discovery

The vulnerability was disclosed in Acronis advisory SEC-10986. Available reporting does not name an external reporter. There is no NVD record as of the KEV listing date, so the CVSS score above is the vendor's assignment.

Exploitation Context

Acronis reported that the flaw has been observed in limited, targeted attacks against cPanel & WHM deployments specifically. As of reporting there were no signs of exploitation against Plesk deployments. No threat-actor attribution, no confirmed chaining with other CVEs, and no public proof of concept had been published as of 2026-09-16. CISA's same-day KEV listing reflects the confirmed exploitation Acronis described.

Remediation

  1. Update the plugin and extension to Acronis Backup plugin for cPanel & WHM 1.9.3 HF3 (or later) and Acronis Backup extension for Plesk 1.8.11 (or later) immediately.
  2. Review file permissions on the Acronis backup component paths after updating, to confirm the insecure defaults were corrected and were not re-loosened by a prior installation.
  3. Hunt for local escalation on affected hosts, especially cPanel & WHM servers: unexpected privilege changes, new or modified administrator-level cPanel accounts, and files owned by unexpected users under the Acronis and backup directories.
  4. Prioritize multi-tenant servers. On shared hosting, a single compromised low-privilege account is the realistic starting point, so patch tenant-facing hosts first.
  5. Rotate credentials on any host where an indicator is found, including panel administrator passwords and backup-service credentials.

Key Details

PropertyValue
CVE ID CVE-2026-87886
Vendor / Product Acronis — Backup
CVSS 3.1 ScorePending
SeverityUNKNOWN
CISA KEV Added2026-09-16
CISA KEV Deadline2026-09-19
Known Ransomware Use No

Required Action

CISA BOD 22-01 Deadline: 2026-09-19. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2026-09-16Acronis publishes advisory SEC-10986; CVE added to CISA Known Exploited Vulnerabilities catalog
2026-09-19CISA BOD 22-01 remediation deadline