Acronis Backup Insecure File Permissions Local Privilege Escalation

Release Date: 16th September 2026 (Added 21 September 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-87886 is a high-severity local privilege escalation vulnerability affecting Acronis's Linux-based backup integrations for hosting control panels. The flaw resides in insecure file permissions within the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk, both of which link these widely-used hosting management platforms to Acronis's backup and recovery infrastructure.

Reference

  1. https://security-advisory.acronis.com/advisories/SEC-10986
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-87886