highOther

Acronis Backup Incorrect Default Permissions Vulnerability

First seen Sep 17, 2026 · Updated Sep 17, 2026

privilege-escalationcisa-kevacroniscpanelwhmpleskbackup-softwareactive-exploitation

CVE-2026-87886 is a known-exploited vulnerability in the Acronis Backup plugin for cPanel & WHM and the corresponding extension for Plesk, caused by incorrect default file/permission settings. The flaw allows a local attacker to escalate privileges on affected hosting control panel servers. CISA added this to its Known Exploited Vulnerabilities catalog with a short remediation window (added 2026-09-16, due 2026-09-19), indicating active exploitation in the wild.

Technical Analysis

CVE-2026-87886 stems from overly permissive default file or directory permissions set by the Acronis Backup plugin when installed on cPanel & WHM or Plesk hosting environments. This misconfiguration can allow a low-privileged local user to read, modify, or replace sensitive files (such as configuration files, credentials, or executable scripts) that are later executed or trusted by a higher-privileged process, enabling privilege escalation to root/administrator on shared or dedicated hosting servers. Exploitation likely requires local or web-shell-level access already obtained through another vector (e.g., a compromised hosting account or web application), after which the attacker leverages the weak permissions to pivot to full server control. CISA's inclusion in the KEV catalog with a 3-day remediation deadline confirms this is being actively exploited, making unpatched cPanel/WHM/Plesk servers a priority target for both opportunistic and targeted attackers. Organizations that host AI agent orchestration services, RAG pipelines, or LLM API gateways on shared cPanel/Plesk hosting infrastructure could see backup credentials, API keys, and agent configuration files exposed or tampered with if an attacker escalates privileges via this flaw, so hosting environments running agent-adjacent workloads should be prioritized for patching.

Affected Systems

Acronis Backup plugin for cPanel & WHM (all vulnerable versions prior to vendor patch); Acronis Backup extension for Plesk (all vulnerable versions prior to vendor patch); hosting servers running cPanel & WHM or Plesk control panels with the Acronis Backup integration installed

Indicators of Compromise

  • No specific file hashes, IPs, or domains published at time of disclosure; monitor Acronis and CISA KEV advisories for indicator updates

Remediation Steps

  1. 1

    Apply vendor patch

    Update the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk to the latest vendor-released version that corrects the default permissions issue.

  2. 2

    Audit file permissions

    Manually review and correct permissions on Acronis Backup installation directories, configuration files, and related binaries on all affected servers to ensure least-privilege access.

  3. 3

    Restrict local account access

    Limit shell and local account access on shared hosting servers to reduce the attack surface available for exploiting local privilege escalation flaws.

  4. 4

    Monitor for exploitation indicators

    Review server logs for unauthorized privilege changes, unexpected root/administrator processes, or modifications to Acronis Backup files since the vulnerability disclosure date.

  5. 5

    Comply with CISA KEV deadline

    Federal agencies and organizations following CISA KEV guidance should remediate by the 2026-09-19 due date; all organizations are strongly encouraged to prioritize patching given confirmed active exploitation.

CVE / Advisory IDs

CVE-2026-87886

Industries Most Exposed

web hostingmanaged service providersIT infrastructurecloud servicesany industry using cPanel/Plesk-based hosting for backup or web operations

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.