Understanding the Acronis Backup Vulnerability
A significant security flaw has been identified in several Acronis Backup plugins and extensions for Linux-based server environments. This vulnerability, tracked as CVE-2026-87886, could allow an attacker who already has basic access to a system to gain higher-level permissions. This type of attack is known as “local privilege escalation.” It happens because of insecure file permissions within the affected Acronis products, which could be exploited to compromise the system further.
CVE Details
This vulnerability impacts the Acronis Backup plugins designed for cPanel & WHM, Plesk, and DirectAdmin platforms on Linux. It was publicly disclosed on September 17, 2026, and is currently under “Analyzed” status, meaning it has been reviewed and understood by security researchers and vendors.
- Product: Acronis Backup plugin for cPanel & WHM (Linux), Acronis Backup extension for Plesk (Linux), Acronis Backup plugin for DirectAdmin (Linux)
- Published Date: September 17, 2026
- Severity: N/A (Not officially assigned, but privilege escalation is generally a serious concern)
- Status: Analyzed
Affected Products
The following specific versions of Acronis Backup products are vulnerable to this issue due to insecure file permissions:
- Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021
- Acronis Backup extension for Plesk (Linux) before build 1.8.11.638
- Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238
Current Status
The vulnerability, CVE-2026-87886, is currently in an “Analyzed” state. This indicates that the details of the flaw have been investigated and confirmed by the relevant parties. Users should stay vigilant for official updates and advisories from Acronis regarding any further developments or newly released patches.
Severity Level
While an official CVSS severity score for CVE-2026-87886 is not available and is listed as “N/A,” it’s important to understand the implications of a local privilege escalation vulnerability. Such flaws can be highly critical because they allow an attacker who has already gained a foothold on a system (even with low-level access) to elevate their privileges to that of a system administrator or root user. This could lead to complete system compromise, data theft, or further malicious activity. Therefore, even without a numerical score, this type of vulnerability should be taken very seriously by administrators.
Possible Solutions
Acronis has released updated builds to address this insecure file permissions vulnerability. To secure your systems against CVE-2026-87886, it is crucial to update your Acronis Backup installations to the patched versions as soon as possible. Specifically, users should:
- Update Acronis Backup plugin for cPanel & WHM (Linux) to build 1.9.3.1021 or later.
- Update Acronis Backup extension for Plesk (Linux) to build 1.8.11.638 or later.
- Update Acronis Backup plugin for DirectAdmin (Linux) to build 1.2.3.238 or later.
Always ensure that you follow official patching procedures and test updates in a non-production environment if possible before deploying them widely. Regular security audits and ensuring proper file permissions are maintained across your server environment are also key practices in preventing similar issues. For more insights into privilege escalation, consider reading Understanding Local Privilege Escalation Attacks. Also, check out Securing Your cPanel and WHM Environment for broader security tips.
References
https://security-advisory.acronis.com/advisories/SEC-10986
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87886



