Impact
The vulnerability arises from insecure file permissions set by the Acronis Backup plugins, allowing a local user to elevate privileges. An attacker who can write or delete files in the backup directories can manipulate permission settings, thereby gaining root‑level access to the host system. The weakness is a classic example of incorrect authorization and is identified as CWE‑276.
Affected Systems
Affected products include Acronis Backup plugin for cPanel & WHM for Linux versions before build 1.9.3.1021, Acronis Backup extension for Plesk for Linux before build 1.8.11.638, and Acronis Backup plugin for DirectAdmin for Linux before build 1.2.3.238. The vulnerability is bundled with the Acronis Backup suite across these control panel environments.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. However, being listed in the CISA KEV catalog confirms that at least one exploitation instance may already exist. The attack requires local access to the machine; an attacker can modify file permissions to gain root privileges without needing remote code execution. With such elevated privileges, the attacker could exfiltrate data, modify backups, or maintain persistent access.
OpenCVE Enrichment