Acronis Backup Plugin Vulnerability in cPanel and Plesk Exploited in Limited Attacks
Acronis has released security updates for its Backup plugin for cPanel & WHM and Backup extension for Plesk to address CVE-2026-87886, a high-severity local privilege escalation flaw exploited in targeted attacks.

Acronis has issued urgent security updates for its widely used Backup plugin for cPanel & WHM and its Backup extension for Plesk, following the discovery of limited, targeted exploitation of a critical vulnerability. The flaw, identified as CVE-2026-87886, is a local privilege escalation vulnerability stemming from insecure file permissions within the Linux-based Acronis backup components.
With a CVSS score of 7.8, the vulnerability is classified as high severity. Acronis has strongly advised all users of the affected products to apply the available patches immediately to mitigate the risk of compromise. The vulnerability falls under the CWE-276 classification, which denotes incorrect default permissions. Such misconfigurations can lead to unauthorized access to sensitive files or allow low-privileged accounts to access resources beyond their intended scope.
Exploitation of CVE-2026-87886 requires an attacker to already possess local access to a vulnerable system, with low-level privileges being sufficient. Crucially, the attack does not necessitate any user interaction, making it a potent threat for adversaries who have already gained a foothold on a server. Successful exploitation could grant an attacker elevated privileges, thereby compromising the confidentiality, integrity, and availability of the affected system.
In practical scenarios, a threat actor with existing access to a compromised Linux hosting server—obtained through methods like a breached hosting account, weak credentials, a vulnerable web application, or other initial access vectors—could leverage this Acronis vulnerability. This could potentially unlock access to sensitive backup data, critical system files, the hosting control-panel environment itself, or even other customer accounts hosted on the same infrastructure.
Acronis has stated that it has only observed exploitation in limited, targeted attacks. However, the public disclosure of the vulnerability and the release of patches often precede a surge in exploitation attempts. Attackers frequently begin scanning for vulnerable systems once security fixes become known, increasing the urgency for immediate patching.
The vulnerability has been addressed in version 1.9.3 HF3 of the Acronis Backup plugin for cPanel & WHM. For Plesk environments, the fix is included in version 1.8.11 of the Acronis Backup extension. Administrators managing these platforms are urged to verify their installed versions and upgrade to the patched releases without delay.
Given that cPanel and Plesk servers often host multiple websites and diverse customer workloads, managed service providers and hosting companies should prioritize this update. A local privilege escalation flaw within these environments can significantly amplify the impact of an initial compromise. Security teams should also actively monitor their servers for any signs of unauthorized local access, unexpected privilege escalations, suspicious processes running with elevated permissions, or unusual modifications to Acronis-related files and directories.
Organizations unable to patch immediately are advised to implement interim mitigation strategies. These include restricting local access to affected servers, limiting shell access for untrusted accounts, enhancing monitoring of privileged activities, and, where feasible, isolating backup infrastructure from standard hosting workloads to minimize the potential blast radius of a successful attack.
The article confirms that the vulnerability, tracked as CVE-2026-87886, has been exploited in the wild in limited, targeted attacks against the Acronis Backup plugin for cPanel & WHM. Acronis has released patches for affected Linux versions of the plugin prior to build 1.9.3.1021, and for the Backup extension for Plesk prior to build 1.8.11.638.
The vulnerability, identified as CVE-2026-87886, stems from insecure file permissions and allows authenticated attackers to achieve local privilege escalation with low complexity. While Acronis has released patches for the affected plugins, details regarding the specific tactics used by attackers in the wild remain undisclosed.