← Vulnerability feed

Vulnerability record · CVE-2026-87886 · published 17 September 2026

CVE-2026-87886: Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalation

Acronis · Acronis Backup

Acronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escalate privileges. The flaw is rated CVSS 3.0 7.8 (HIGH) and was added to CISA KEV, so it warrants prompt remediation on any host running the affected builds.

7.8 CVSS 3.0 High CISA KEV since 16 Sep 2026 EPSS 0.23% · top 87.2% CWE-276 · Incorrect default permissions
7.8CVSS 3.0 base score
0.23%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
18 Sep 2026Last modified by NVD

Description

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.8 with local low-privilege reach and CISA KEV listing make this a high-priority fix despite the absence of EPSS data and exploit detail.

What it is

Acronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escalate privileges. The flaw is rated CVSS 3.0 7.8 (HIGH) and was added to CISA KEV, so it warrants prompt remediation on any host running the affected builds.

Impact

An attacker with a local account gains high confidentiality, integrity and availability impact on the host, effectively full control of the system and any backup data or credentials it can reach.

Attack surface

The vector is local (AV:L) with low attack complexity, low privileges required and no user interaction, so any unprivileged local user or process on an affected Linux host can reach it. No remote or network path is described in the record.

Exploitation

The record is listed in CISA KEV with a 2026-09-19 remediation due date, indicating known exploitation, but no ransomware campaign use is documented and EPSS is unknown. The single reference carries no exploit tags.

What to do

  • Upgrade to the fixed builds: Acronis Backup plugin for cPanel & WHM 1.9.3.1021 or later, Plesk extension 1.8.11.638 or later, DirectAdmin plugin 1.2.3.238 or later.
  • If patching cannot be done immediately, restrict local login and shell access on affected hosts to trusted administrators only.
  • Audit and correct file and directory permissions on Acronis plugin install paths so unprivileged users cannot write to or replace privileged files.
  • Follow CISA BOD 26-04 guidance for affected assets, including evaluating internet exposure and applying the required triage actions.
  • Track the vendor advisory SEC-10986 for updated fixed builds or interim guidance.

Detection

  • Monitor for unexpected writes or permission changes to Acronis plugin directories and binaries on cPanel, Plesk and DirectAdmin hosts.
  • Alert on local privilege escalation behavior such as processes gaining root from unprivileged accounts shortly after touching Acronis plugin files.
  • Inventory hosts for the affected plugin builds and flag any that remain below the fixed versions.
  • Review local account creation or sudo/root activity on backup servers for signs of post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-87886 to the Known Exploited Vulnerabilities catalog on 16 September 2026 as "Acronis Backup Incorrect Default Permissions Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-87886 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-87886), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.