Acronis Backup Plugins for cPanel and Plesk Carry Actively Exploited Privilege-Escalation Flaw

Acronis has disclosed a high-severity local privilege-escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM) and Plesk, warning that it has detected exploitation in the wild. The flaw, tracked as CVE-2026-87886, carries a CVSS severity score of 7.8 and allows a low-privileged attacker to increase their permission level on a vulnerable Linux server without user interaction, potentially enabling access to or modification of sensitive data, according to Acronis’s advisory.

The plugins connect the widely used cPanel and Plesk hosting control panels to Acronis’s backup infrastructure, letting administrators back up and restore websites, databases, mailboxes and hosting accounts. Acronis said exploitation “has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” though it told BleepingComputer the assessment is based on a single report from a potentially affected customer.

Affected versions include the Acronis Backup plugin for cPanel & WHM prior to build 1.9.3.1021, fixed in version 1.9.3 HF3, and the Acronis Backup extension for Plesk prior to build 1.8.11.638, fixed in version 1.8.11. Acronis is urging all users of the affected integrations to update immediately.

Why it matters

Backup plugins run with elevated privileges by design, which is exactly what makes a privilege-escalation flaw in one valuable to an attacker who already has limited server access; hosting operators should treat the patch as time-sensitive rather than routine.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *