Description
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: Yes
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from insecure file permissions set by the Acronis Backup plugins, allowing a local user to elevate privileges. An attacker who can write or delete files in the backup directories can manipulate permission settings, thereby gaining root‑level access to the host system. The weakness is a classic example of incorrect authorization and is identified as CWE‑276.

Affected Systems

Affected products include Acronis Backup plugin for cPanel & WHM for Linux versions before build 1.9.3.1021, Acronis Backup extension for Plesk for Linux before build 1.8.11.638, and Acronis Backup plugin for DirectAdmin for Linux before build 1.2.3.238. The vulnerability is bundled with the Acronis Backup suite across these control panel environments.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. However, being listed in the CISA KEV catalog confirms that at least one exploitation instance may already exist. The attack requires local access to the machine; an attacker can modify file permissions to gain root privileges without needing remote code execution. With such elevated privileges, the attacker could exfiltrate data, modify backups, or maintain persistent access.

Generated by OpenCVE AI on September 18, 2026 at 23:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest vendor‑supplied updates, ensuring the build numbers are at least 1.9.3.1021 for the cPanel & WHM plugin, 1.8.11.638 for the Plesk extension, and 1.2.3.238 for the DirectAdmin plugin.
  • Verify that backup directories and configuration files are owned by the backup service user and have permissions set to 640 or tighter, preventing unauthorized modification.
  • Apply least‑privilege principles to the backup service, restricting its execution context and limiting network exposure to only necessary control panel components.

Generated by OpenCVE AI on September 18, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Insecure File Permissions in Acronis Backup Plugins

Fri, 18 Sep 2026 15:30:00 +0000


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Acronis acronis Backup
Linux
Linux linux Kernel
CPEs cpe:2.3:a:acronis:acronis_backup:*:*:*:*:*:cpanel:*:*
cpe:2.3:a:acronis:acronis_backup:*:*:*:*:*:directadmin:*:*
cpe:2.3:a:acronis:acronis_backup:*:*:*:*:*:plesk:*:*
cpe:2.3:a:acronis:acronis_backup:1.9.3:-:*:*:*:cpanel:*:*
cpe:2.3:a:acronis:acronis_backup:1.9.3:hotfix1:*:*:*:cpanel:*:*
cpe:2.3:a:acronis:acronis_backup:1.9.3:hotfix2:*:*:*:cpanel:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Acronis acronis Backup
Linux
Linux linux Kernel
References

Fri, 18 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Acronis
Acronis backup Extension For Plesk
Acronis backup Plugin For Cpanel \& Whm
Acronis backup Plugin For Directadmin
Vendors & Products Acronis
Acronis backup Extension For Plesk
Acronis backup Plugin For Cpanel \& Whm
Acronis backup Plugin For Directadmin

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.4.238. Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.4.238.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

kev

{'dateAdded': '2026-09-16T00:00:00+00:00', 'dueDate': '2026-09-19T00:00:00+00:00'}


Subscriptions

Acronis Acronis Backup Backup Extension For Plesk Backup Plugin For Cpanel \& Whm Backup Plugin For Directadmin
Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Acronis

Published:

Updated: 2026-09-18T14:33:42.532Z

Reserved: 2026-09-09T14:04:36.755Z

Link: CVE-2026-87886

cve-icon Vulnrichment

Updated: 2026-09-18T12:28:18.163Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T23:18:53.763

Modified: 2026-09-18T19:29:35.067

Link: CVE-2026-87886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:30:15Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions