Acronis has patched a privilege-escalation flaw in the backup plugin it offers hosting providers running cPanel and WHM, and says the flaw has been used in “limited, targeted attacks” against servers with the plugin installed. The vulnerability, CVE-2026-87886, comes from insecure file permissions and is scored 7.8, high. The fix for cPanel and WHM is version 1.9.3 HF3, build 1.9.3.1021, released September 11. The company’s Backup extension for Plesk carries the same flaw. Its security notice, published September 10, identifies build 1.8.11.638 as the fixed build, and the product’s release notes date that build to June 3. Acronis reports no signs of exploitation on Plesk deployments. On September 16 the US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog, with a September 19 deadline for US federal civilian agencies.
What Acronis has published is short. The advisory, dated September 15, gives the CVE number, the score and vector, the two affected products and one sentence on exploitation. Technical details are being held back to give administrators time to update, BleepingComputer reported. The same outlet reported a second detail about the evidence: Acronis said its assessment of in-the-wild exploitation rests on a single report from a “potentially affected” customer. The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what the attackers achieved beyond the escalation the advisory describes.
Key facts
- The flaw: insecure file permissions in the Acronis Backup plugin for cPanel and WHM and in the Backup extension for Plesk allow a local, low-privileged user to gain elevated privileges. Acronis scores it 7.8.
- The fix: plugin build 1.9.3.1021 (version 1.9.3 HF3, released September 11) for cPanel and WHM, and extension build 1.8.11.638 (version 1.8.11, released June 3, security notice September 10) for Plesk, both Linux.
- Exploitation: Acronis reports limited, targeted attacks on cPanel and WHM deployments only, based on one customer report, with no indicators of compromise identified.
- The deadline: CISA listed the flaw on September 16 and gave US federal civilian agencies until September 19 to act.
Who Has This Plugin and Who Can Reach It
The Acronis Backup plugin is not something a website owner installs. Acronis describes it as “built for Hosting and Cloud service providers,” an add-on for cPanel and WHM servers connecting the control panel to Acronis Cyber Protect Cloud so that whole servers are backed up and individual accounts can be restored from inside the panel. According to the plugin’s manual, it is installed from a terminal on the server by an administrator or root, sets up its own protection agent, and is updated with a package command, yum update acronis-backup-cpanel on RPM-based systems or the apt equivalent on Ubuntu. That puts the update in the administrator’s hands, not the customer’s.
The plugin also has a customer-facing side. The manual states that “only the server administrator has permission to manage backups on the web hosting server,” while “resellers and end users can only access and restore their data if the self-service recovery feature is available for their accounts.” When it is, an account with the Acronis privilege enabled can browse its backups and download or recover domains, files, databases, mailboxes and, the manual says, entire accounts.
The CVSS vector Acronis published, local access with low privileges and no user interaction, describes an attacker who already has a limited foothold on the server. On a shared cPanel host, a compromised website or another process that gives an attacker code execution under a hosting account could satisfy that prerequisite. That is consistent with the vector, not a description of how the reported attack worked, because Acronis has not said how it worked. What the vector does establish is that the attacker has to be on the server already, and that the damage the flaw allows is rated high on confidentiality, integrity and availability alike.
It follows another privilege-escalation flaw on cPanel servers patched this month. On September 8, cPanel fixed CVE-2026-67401 in its own software, a flaw through which a mail-privileged account could reach root. The two are unrelated: one sits in cPanel, the other in a third-party plugin, and only the Acronis flaw is in CISA’s catalog.
One Flaw, Two Update Notices
Acronis publishes update notices per product, and the two notices for this flaw are not the same. The Plesk notice of September 10 says the update “is recommended for all users” and that the company sees “no signs of active exploitation.” The cPanel and WHM notice of September 11 says the update “should be installed immediately by all users” and that exploitation “has been detected in the wild in limited, targeted attacks.” The umbrella advisory that followed on September 15 repeats the cPanel wording and adds that the attacks were “against Acronis Backup plugin for cPanel & WHM deployments.”
The release notes give the two fixes different histories. The Plesk build the notice points to, 638, is dated June 3 in the extension’s release notes, so the fixed build had been available for three months before the notice named it. The cPanel build, 1021, is dated September 11, the day of its notice. On the same day Acronis also released version 1.9.4 of the cPanel plugin, build 1022, which requires a newer protection agent than the hotfix does.
CISA’s catalog entry names both products under the heading “Acronis Backup Incorrect Default Permissions Vulnerability,” lists ransomware use as unknown, and ties the September 19 deadline to Binding Operational Directive 26-04. For commercial hosting providers, the deadline is not binding. The listing itself is the signal, since CISA says it adds flaws on evidence of active exploitation. A spokesperson told The Hacker News the company had nothing to add at this stage. For anyone running either integration, the immediate action is straightforward: verify that cPanel and WHM deployments are on build 1021 (version 1.9.3 HF3) or later, and Plesk deployments on build 638 (version 1.8.11) or later, and install the latest available release if they are not.
About the Data
The flaw’s identifier, score, vector, affected builds and exploitation statement come from Acronis’s advisory SEC-10986 and its two product update notices. Build release dates come from each product’s release notes. Acronis’s statement that its assessment rests on one customer report was made to BleepingComputer, which also reported that no indicators of compromise had been identified. CISA’s listing, deadline and wording come from its Known Exploited Vulnerabilities feed and September 16 alert. The reading of the CVSS vector is ours and describes a possible prerequisite, not the attack path, which Acronis has not published.
Sources
- Local privilege escalation due to insecure file permissions (SEC-10986) - Acronis Advisory Database
- Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 - Acronis Advisory Database
- Acronis Backup extension for Plesk version 1.8.11 - Acronis Advisory Database
- Acronis Backup plugin for cPanel & WHM: release notes - Acronis
- Acronis Backup extension for Plesk: release notes - Acronis
- CISA Adds Two Known Exploited Vulnerabilities to Catalog - CISA
- Known Exploited Vulnerabilities Catalog - CISA
- Acronis warns of actively exploited flaw in its cPanel backup plugin - BleepingComputer
- Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks - The Hacker News
- Acronis Backup plugin for cPanel & WHM (manual, PDF) - Acronis
- Acronis Cyber Protect Cloud integration with cPanel & WHM - Acronis
- CVE-2026-67401 - CVE Program