Acronis Backup Incorrect Default Permissions Vulnerability
First seen Sep 17, 2026 · Updated Sep 17, 2026
CVE-2026-87886 is a known-exploited vulnerability in the Acronis Backup plugin for cPanel & WHM and the corresponding extension for Plesk, caused by incorrect default file/permission settings. The flaw allows a local attacker to escalate privileges on affected hosting control panel servers. CISA added this to its Known Exploited Vulnerabilities catalog with a short remediation window (added 2026-09-16, due 2026-09-19), indicating active exploitation in the wild.
Technical Analysis
CVE-2026-87886 stems from overly permissive default file or directory permissions set by the Acronis Backup plugin when installed on cPanel & WHM or Plesk hosting environments. This misconfiguration can allow a low-privileged local user to read, modify, or replace sensitive files (such as configuration files, credentials, or executable scripts) that are later executed or trusted by a higher-privileged process, enabling privilege escalation to root/administrator on shared or dedicated hosting servers. Exploitation likely requires local or web-shell-level access already obtained through another vector (e.g., a compromised hosting account or web application), after which the attacker leverages the weak permissions to pivot to full server control. CISA's inclusion in the KEV catalog with a 3-day remediation deadline confirms this is being actively exploited, making unpatched cPanel/WHM/Plesk servers a priority target for both opportunistic and targeted attackers. Organizations that host AI agent orchestration services, RAG pipelines, or LLM API gateways on shared cPanel/Plesk hosting infrastructure could see backup credentials, API keys, and agent configuration files exposed or tampered with if an attacker escalates privileges via this flaw, so hosting environments running agent-adjacent workloads should be prioritized for patching.
Affected Systems
Acronis Backup plugin for cPanel & WHM (all vulnerable versions prior to vendor patch); Acronis Backup extension for Plesk (all vulnerable versions prior to vendor patch); hosting servers running cPanel & WHM or Plesk control panels with the Acronis Backup integration installed
Indicators of Compromise
- No specific file hashes, IPs, or domains published at time of disclosure; monitor Acronis and CISA KEV advisories for indicator updates
Remediation Steps
- 1
Apply vendor patch
Update the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk to the latest vendor-released version that corrects the default permissions issue.
- 2
Audit file permissions
Manually review and correct permissions on Acronis Backup installation directories, configuration files, and related binaries on all affected servers to ensure least-privilege access.
- 3
Restrict local account access
Limit shell and local account access on shared hosting servers to reduce the attack surface available for exploiting local privilege escalation flaws.
- 4
Monitor for exploitation indicators
Review server logs for unauthorized privilege changes, unexpected root/administrator processes, or modifications to Acronis Backup files since the vulnerability disclosure date.
- 5
Comply with CISA KEV deadline
Federal agencies and organizations following CISA KEV guidance should remediate by the 2026-09-19 due date; all organizations are strongly encouraged to prioritize patching given confirmed active exploitation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.