Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis warns of a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk. The vulnerability may be exploited in the wild.
Intelligence analysis by Qwen 2.5 (3B)

Acronis has disclosed a critical vulnerability in its backup plugin for cPanel, WHM, and Plesk. The flaw could allow attackers to escalate privileges and access sensitive data.
This is like if someone found a secret door in your house that lets them become the boss of your whole neighborhood. The company that made the door knows about it and is telling everyone to fix it quickly to keep bad guys from using it.
Analysis
{"heading":"Technical Details of CVE-2026-87886","subheading":"Privilege Escalation Vulnerability","paragraphs":["CVE-2026-87886 is a local privilege escalation vulnerability affecting Acronis Backup plugin for cPanel, WHM, and Plesk. The vulnerability allows a low-privileged attacker to increase their permission level on a vulnerable Linux server.","The vulnerability was identified in Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638.","Acronis has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory."]}
Key points
- Acronis warns of a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk.
- The vulnerability affects Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638.
- Users are recommended to apply the available updates immediately to protect their systems.
Users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately to protect their systems.
If the vulnerability is exploited, attackers could gain control over sensitive data and disrupt the system without user interaction.


