Impact
Acronis Cyber Protect 17 contains an authorization flaw that allows an attacker to read sensitive data or alter system state beyond the intended privileges. This weakness is catalogued as CWE-863, highlighting that authentication controls are insufficient. Consequently, confidential information may be exposed and data integrity affected, potentially impacting all users of the affected installation.
Affected Systems
The vulnerability applies to the Linux and Windows editions of Acronis Cyber Protect 17 that run before build 41186. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate risk level, while the EPSS score of less than 1% suggests that the likelihood of exploitation is low at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely exploit the flaw through an authenticated or local user context, or by abusing a service that allows unauthorized access. Without a direct privilege escalation path, the vector remains limited, but still poses a confidentiality and integrity concern.
OpenCVE Enrichment