highZero-Day

Acronis Cyber Protect / Backup Plugin Local Privilege Escalation (cPanel/WHM/Plesk)

First seen Sep 16, 2026 · Updated Sep 16, 2026

linuxprivilege-escalationcpanelwhmpleskweb-hostingacronisactively-exploited

Acronis has disclosed a high-severity local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk that is reportedly being exploited in the wild. The flaw allows a local attacker with limited access to escalate privileges on affected Linux hosting servers, potentially leading to full system compromise.

Technical Analysis

The vulnerability resides in Acronis' backup plugin integration for cPanel/WHM and Plesk control panels on Linux systems, allowing a local unprivileged user or process to escalate to root-level privileges. Exploitation likely involves insecure file permissions, race conditions, or improper privilege-dropping within the plugin's backup execution routines, though a specific CVE identifier has not yet been confirmed in the source reporting. Active exploitation in the wild suggests attackers already possess working exploit code or a reliable technique, increasing urgency for patching. Because hosting servers running cPanel/WHM/Plesk frequently host multi-tenant environments including CI/CD pipelines and backend services, successful escalation could grant attackers full control over co-located workloads. Organizations that self-host AI agent orchestration, RAG pipelines, or LLM tool-use backends on shared or unpatched cPanel/WHM/Plesk infrastructure face risk of credential theft (API keys, model provider tokens) and lateral movement into agent frameworks if the underlying host is compromised.

Affected Systems

Acronis Cyber Protect/Backup plugin for cPanel & WHM on Linux; Acronis backup plugin for Plesk on Linux; hosting servers running affected plugin versions (specific version numbers not disclosed in source data)

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) disclosed in available reporting

Remediation Steps

  1. 1

    Apply vendor patch

    Update the Acronis backup plugin for cPanel, WHM, and Plesk to the latest patched version as soon as it is released by Acronis.

  2. 2

    Restrict local access

    Limit shell and local account access on hosting servers to trusted administrators only, reducing the attack surface for local privilege escalation.

  3. 3

    Monitor for exploitation indicators

    Review system logs, cron jobs, and privilege escalation attempts (e.g., unexpected root shell spawns or SUID abuse) on servers running the affected plugin.

  4. 4

    Isolate hosting environments

    Where possible, segment multi-tenant hosting environments and any co-located AI agent or automation workloads from general-purpose hosting infrastructure.

  5. 5

    Rotate credentials

    If compromise is suspected, rotate API keys, service account credentials, and secrets accessible from the affected host, including those used by AI agents or automation tooling.

Industries Most Exposed

web hostingmanaged service providersIT infrastructureSaaStechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.