Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Vulnerabilities
CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation.
Acronis on Tuesday rolled out urgent patches for a vulnerability in the Backup plugin for cPanel & WHM that has been exploited in the wild.
The Acronis Backup plugin for cPanel & WHM provides disk-level backup and recovery capabilities across hosting control panel environments.
Insecure file permissions in the backup tool and in the Backup extension for Plesk can allow attackers to gain elevated privileges.
The vulnerability is tracked as CVE-2026-87886 (CVSS score of 7.8) and has been exploited in the wild against the plugin, but not against the extension.
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” Acronis notes in its advisory.
The company says all Linux versions of the Backup plugin for cPanel & WHM before...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE