Acronis Warns of Exploited Privilege-Escalation Flaw in cPanel Backup Plugin

Acronis warns CVE-2026-87886 allows local privilege escalation in cPanel & Plesk backup plugins, with limited exploitation reported. Update now.

Text generated by artificial intelligence, published without human review. AI transparency

Acronis Warns of Exploited Privilege-Escalation Flaw in cPanel Backup Plugin
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Acronis has disclosed a high-severity vulnerability in its Linux backup integrations for cPanel & WHM and Plesk, warning that attackers may already have exploited the cPanel component in targeted activity.

Tracked as CVE-2026-87886, the flaw allows a low-privileged attacker with access to a vulnerable server to obtain higher privileges. It carries a CVSS score of 7.8 and does not require another user to perform an action.

Acronis reported the issue on September 15, 2026, following an earlier, shorter advisory. Fixes are available for both affected integrations.

Exploitation Report Is Serious but Narrow

Acronis says it has observed limited exploitation involving the Acronis Backup plugin for cPanel & WHM. However, the evidence disclosed publicly remains restricted.

The company told BleepingComputer that its assessment was based on one report from a customer considered potentially affected. Acronis has not said when the suspected incident occurred or described the attacker’s actions on the server.

No technical artifacts have been released to confirm how the vulnerability was triggered. There are also no published IP addresses, file hashes, filenames, process patterns, commands, or other indicators of compromise associated with the activity.

That leaves defenders with an exploitation warning but no reliable signature for finding it. The available information also does not establish whether multiple organizations were targeted or whether the reported activity resulted in a confirmed compromise.

Exploitation has been associated specifically with the cPanel & WHM plugin. Acronis has not reported in-the-wild attacks against the Plesk extension, although that product is vulnerable to the same tracked issue and should also be updated.

What CVE-2026-87886 Allows an Attacker to Do

CVE-2026-87886 is a local privilege-escalation vulnerability affecting Linux servers running the Acronis control-panel integrations.

An attacker must already possess some level of access to the affected host. This could be a low-privileged account or another form of local execution, but Acronis has not described the precise prerequisite or published a proof of concept.

The flaw is therefore not presented as a direct, unauthenticated route into an internet-facing server. Instead, it can turn limited access into a more powerful position after an attacker has reached the system.

Successful exploitation may allow the attacker to read or modify sensitive information and interfere with server operations. The exact privilege level obtained after exploitation has not been disclosed, so it cannot be confirmed from the available information whether the flaw always grants full root access.

The risk is particularly relevant in hosting environments. cPanel & WHM and Plesk provide graphical administration of websites, databases, mailboxes, files, and hosting accounts. Acronis integrates backup and restoration functions into those environments.

Consequently, an attacker who escalates privileges on a hosting server could potentially affect more than one administrative function. The actual impact would depend on the attacker’s resulting permissions, the server configuration, and the resources hosted on that machine.

Acronis is withholding deeper technical details while customers deploy the fixes. The vulnerable component, triggering condition, exploitation procedure, and expected forensic traces are not currently known.

Vulnerable Builds and Corrected Releases

The vulnerability affects separate Acronis integrations for the two hosting-control-panel platforms.

Acronis product Vulnerable builds Corrected release
Acronis Backup plugin for cPanel & WHM Builds earlier than 1.9.3.1021 1.9.3 HF3
Acronis Backup extension for Plesk Builds earlier than 1.8.11.638 1.8.11

Administrators should check the installed build number rather than relying only on a shortened version label. For the cPanel plugin, the deployed build should not be below 1.9.3.1021. For the Plesk extension, it should not be below 1.8.11.638.

The cPanel naming may require particular attention because the fixed release is identified as 1.9.3 HF3, while exposure is defined by the complete build number. Organizations should confirm both the displayed release and underlying build after installation.

Acronis has not provided a configuration workaround or compensating change that removes the vulnerability without updating. Patching is therefore the primary remediation.

Hosting Providers Need to Assess Both Exposure and Access

Organizations running either integration should install the corrected version immediately, then verify that the update completed across every relevant Linux host.

This verification matters in fleets where plugins may be deployed through different control panels, templates, automation systems, or server images. A successful update on one management node does not demonstrate that every hosting server is protected.

Defenders should first inventory systems running:

  • Acronis Backup plugin for cPanel & WHM;
  • Acronis Backup extension for Plesk;
  • vulnerable builds identified in the version table;
  • older server images or templates that could redeploy an exposed build.

They should then determine which users, applications, and services had low-privileged access to those hosts. Because this is a local escalation flaw, evidence of an initial foothold may be as significant as evidence of the escalation itself.

Hosting providers should also consider whether potentially exposed systems manage multiple customer websites or accounts. A single vulnerable server could have a wider operational effect than an endpoint assigned to one employee, although no specific cross-account compromise has been documented.

Where practical, vulnerable systems should be prioritized according to internet exposure, number of hosted accounts, administrative importance, and evidence of suspicious access.

Detection Must Rely on Broad Host Telemetry

The absence of vendor-provided indicators makes a conventional indicator search insufficient. Security teams need to look for behavioral evidence across the affected period, though the date of the reported exploitation is not known.

Useful review areas include:

  • unexpected successful or failed authentication events;
  • privilege changes involving low-trust accounts;
  • new or modified administrative users;
  • unusual command execution by control-panel or backup-related processes;
  • processes launched under unexpected user identities;
  • unexplained changes to protected files, permissions, startup settings, or scheduled tasks;
  • abnormal access to website, mailbox, database, account, or backup data;
  • service interruptions or administrative actions without a corresponding change record;
  • suspicious control-panel sessions and backup or restore operations.

Teams should correlate control-panel logs with Linux authentication, process, file-integrity, and administrative-event telemetry. Reviewing only the Acronis interface may miss activity performed directly on the underlying host after privileges were elevated.

If suspicious behavior is found, responders should preserve logs and forensic evidence before making broad cleanup changes. They should also rotate credentials and secrets accessible from the affected server, based on the privileges and data exposed during the suspected incident.

No CISA Known Exploited Vulnerabilities catalog addition date or federal remediation deadline is known for CVE-2026-87886. Recent Acronis vulnerabilities previously added to the KEV catalog have not been identified in the disclosed information, so this incident cannot be reliably placed within a broader KEV pattern.

For now, the actionable path is clear: identify vulnerable builds, deploy the corrected releases, verify installation, and investigate affected Linux hosts without waiting for more detailed indicators.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsAcronis CVE-2026-87886cPanel privilege escalationPlesk backup vulnerabilityCVSS 7.8hosting securitypatch update
Back to home