Acronis Backup Insecure File Permissions Local Privilege Escalation
Release Date: 16th September 2026 (Added 21 September 2026)
Impact : HIGH
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-87886 is a high-severity local privilege escalation vulnerability affecting Acronis's Linux-based backup integrations for hosting control panels. The flaw resides in insecure file permissions within the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk, both of which link these widely-used hosting management platforms to Acronis's backup and recovery infrastructure.
What are the systems affected?
The following version(s) are affected:
- Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021
- Acronis Backup extension for Plesk (Linux) before build 1.8.11.638
Not affected / patched version:
- Acronis Backup plugin for cPanel & WHM (Linux) build 1.9.3 HF3 (1.9.3.1021) and later
- Acronis Backup extension for Plesk (Linux) build 1.8.11.638 and later
What does this mean?
Successful exploitation may allow attackers to:
- Escalate privileges on an affected Linux server from a low-privileged, authenticated account
- Gain elevated access sufficient to perform unauthorized actions or run arbitrary code, affecting the confidentiality and integrity of the hosting environment
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor patch immediately
Upgrade the Acronis Backup plugin for cPanel & WHM to build 1.9.3 HF3 (1.9.3.1021) or later. -
Patch the Plesk extension as well
Upgrade the Acronis Backup extension for Plesk to build 1.8.11.638 or later, even though no exploitation has been reported there yet. -
Prioritize internet-facing hosting environments
-
Apply least privilege
Reference
- https://security-advisory.acronis.com/advisories/SEC-10986
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-87886
- Download advisory (English): Acronis Backup Insecure File Permissions Local Privilege Escalation