Acronis has disclosed a high-severity privilege escalation vulnerability affecting its backup integrations for cPanel, WebHost Manager and Plesk. The company says attackers may already be exploiting the security flaw in limited, targeted attacks.

The vulnerability affects Linux servers and allows a low-privileged attacker to gain additional permissions. Acronis has released security updates and recommends installing them immediately.

Vulnerability Affects Popular Hosting Platforms

The vulnerability, tracked as CVE-2026-87886, received a severity score of 7.8 out of 10.

It affects Acronis backup plugins used with cPanel and WebHost Manager, commonly known as WHM. The problem also affects the company’s backup extension for Plesk.

Web hosting providers and server administrators use cPanel, WHM and Plesk to manage websites and servers through graphical interfaces.

Acronis provides backup integrations for these platforms. The add-ons connect hosting control panels to its infrastructure and allow administrators to manage backups without leaving the interface.

Users can back up or restore websites, files, databases, email accounts and complete hosting accounts. Therefore, a compromise involving the plugin could expose sensitive resources on the affected server.

Attackers Can Increase Their Permissions

CVE-2026-87886 is a local privilege escalation vulnerability. An attacker must first obtain low-level access to a vulnerable Linux server before exploiting it.

Successful exploitation allows the intruder to increase their permission level without user interaction. The attacker could then access or modify sensitive information.

Higher privileges may also allow an intruder to change server configurations, interfere with websites or disrupt hosting services. However, Acronis has not disclosed what attackers achieved during the suspected attacks.

The company has withheld further technical details to give administrators time to install the available patches. This approach may reduce the risk of additional attackers developing working exploits before organisations update their systems.

Acronis Reports Limited Exploitation

Acronis says it detected possible exploitation of the vulnerability in the wild.

According to its security advisory, the activity involved limited and targeted attacks against deployments of the Acronis Backup plugin for cPanel and WHM.

However, the company later clarified that its assessment came from one report involving a potentially affected customer.

Acronis did not reveal when the suspected activity occurred. It also provided no information about the attacker or the intended target.

Furthermore, the company has not shared details about any accessed data, modified systems or operational disruption. The confirmed impact remains limited to the privilege escalation described in the advisory.

Two Acronis Products Require Updates

The Acronis backup flaw affects two product lines.

Acronis Backup plugin for cPanel and WHM builds earlier than 1.9.3.1021 remain vulnerable. Administrators should upgrade those installations to version 1.9.3 HF3.

Acronis Backup extension for Plesk builds earlier than 1.8.11.638 also contain the vulnerability. Version 1.8.11 resolves the problem.

All administrators using the affected integrations should apply the appropriate update immediately. Delaying the patches could leave servers exposed to attacks from users or processes that already have limited access.

No Indicators of Compromise Available

Acronis has not published specific indicators of compromise for CVE-2026-87886.

As a result, administrators cannot rely on a simple list of malicious files, IP addresses or activity patterns to identify exploitation.

Hosting providers should review authentication records and system logs for unusual activity from low-privileged accounts. They should also investigate unexpected permission changes and commands executed with elevated rights.

Unfamiliar changes to websites, databases and email accounts may also indicate unauthorised access. Administrators should pay particular attention to activity that occurred before they installed the patched versions.

Updating the plugin prevents attackers from exploiting this specific flaw in the future. However, it may not remove persistence or reverse changes made during an earlier compromise.

Hosting Providers Should Patch Immediately

The vulnerability creates additional risk because hosting servers often manage numerous websites and customer accounts.

An attacker who gains elevated permissions could potentially access resources belonging to several customers. Moreover, the intruder may use the server to modify websites, steal information or distribute malware.

Administrators should install the updates before Acronis or independent researchers publish additional technical information.

They should also restrict access to hosting control panels and remove accounts that no longer require server access. Strong authentication and continuous monitoring can further reduce the risk of attackers gaining the initial foothold needed to exploit the flaw.

The limited information about the suspected attacks makes the full impact difficult to assess. Nevertheless, the possibility of active exploitation makes prompt patching essential.


0 responses to “Acronis Backup Flaw Exploited in Targeted Attacks”