Acronis Backup Plugin Flaw Exploited
Acronis has disclosed CVE-2026-87886, a high-severity Linux privilege-escalation flaw in its cPanel and Plesk backup plugins, citing limited in-the-wild attacks.
Hosting providers and server administrators rely on Acronis backup integrations to protect websites, databases, and mailboxes from within the familiar interfaces of cPanel, WHM, and Plesk. That convenience now carries a known risk: Acronis has disclosed a high-severity Linux local privilege escalation vulnerability in those plugins, and says it has seen exploitation in the wild.
The flaw and its identifier
The vulnerability was first published in a brief advisory last weekend, but Acronis issued an update today identifying it as CVE-2026-87886 and assigning it a severity score of 7.8. According to the company, a low-privileged attacker can exploit the flaw to increase their permission level on a vulnerable Linux server, potentially accessing or modifying sensitive data and disrupting the system without user interaction.
Further technical details on CVE-2026-87886 have not been published. Acronis said it is withholding that information to give system administrators time to apply the available patches before sharing more. The lack of specifics means defenders currently have little to work with beyond the vendor's advisory and the patch itself.
Limited, targeted attacks detected
Acronis says it has detected exploitation of the vulnerability in the wild, describing the activity as limited and targeted. The advisory warns that exploitation has been observed against Acronis Backup plugin for cPanel & WHM deployments specifically.
“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns.
In a statement for BleepingComputer, Acronis noted that the assessment is based on a single report from a "potentially affected" customer. The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory.
Which versions are affected
The CVE-2026-87886 vulnerability affects specific builds of the Acronis backup integrations. For the Acronis Backup plugin for cPanel & WHM, builds earlier than 1.9.3.1021 are vulnerable; the fix is available in version 1.9.3 HF3. For the Acronis Backup extension for Plesk, builds earlier than 1.8.11.638 are affected, with the fix delivered in version 1.8.11.
The affected products connect the hosting control panel to Acronis infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces. That integration is what makes the privilege-escalation path relevant to shared and managed hosting environments, where multiple tenants may reside on the same server.
Exploitation mechanics and the privilege-escalation path
Privilege escalation flaws like CVE-2026-87886 allow an attacker who already has a low-privileged foothold on a Linux server to elevate their permissions. The advisory states that a low-privileged attacker can exploit the vulnerability to increase their permission level, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction.
In a hosting context, that could mean a compromised user account or a malicious tenant on a shared server could attempt to reach beyond its intended boundaries. Acronis has not detailed the exact mechanism of the flaw, nor has it specified what an attacker could achieve once elevated. The company's decision to withhold technical details until administrators have had time to patch is a common practice, but it also leaves defenders with few proactive detection options beyond applying the update.
No indicators of compromise shared
Acronis has not published specific indicators of compromise related to the detected attacks. The company also did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described in the advisory. That leaves affected organizations unable to hunt for signs of past exploitation based on vendor-provided intelligence.
The advisory does not name any victims, nor does it attribute the attacks to a specific threat actor. The statement to BleepingComputer clarifies that the in-the-wild assessment rests on a single report from a customer that Acronis describes as potentially affected. That is a narrow basis for a warning, but it is enough for the vendor to recommend immediate patching.
Recommended action for administrators
All affected users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately. The fixed versions are 1.9.3 HF3 for the cPanel & WHM plugin and 1.8.11 for the Plesk extension.
Administrators should verify which builds are installed on their servers and update any that fall below the fixed versions. Because the flaw is a local privilege escalation, patching removes the escalation path for an attacker who already has a low-privileged foothold. However, the absence of indicators of compromise means that patching alone may not reveal whether a system was already targeted.
The broader hosting security picture
Control panel integrations like Acronis backup plugins run with elevated privileges to perform backup and restore operations across a server. When a vulnerability in such a plugin allows privilege escalation, it can undermine the isolation that hosting providers depend on to keep tenants separate. The fact that Acronis has seen limited, targeted attacks suggests at least some actors are aware of the flaw and willing to use it.
The company's disclosure timeline—a brief advisory last weekend followed by an update today—reflects a coordinated effort to give administrators time to patch before technical details become public. But with exploitation already detected, the window for silent patching may have closed for some. The lack of shared indicators of compromise makes it harder for defenders to know if they were among the targeted.
What this means for affected organizations
For hosting companies and administrators running Acronis backup integrations, the immediate priority is patching to the fixed versions. The privilege-escalation impact means a successful exploit could allow an attacker to move from a low-privileged account to one with greater access, potentially reaching sensitive data or disrupting services. Given that Acronis has detected limited, targeted attacks, the risk is not purely theoretical.
The single-customer basis for the in-the-wild assessment is a reminder that early warnings can be thin on detail. Organizations should treat the advisory as actionable: check versions, apply updates, and consider whether any additional monitoring for unusual privilege changes is warranted. Because no indicators of compromise have been published, broader threat hunting will rely on internal logs and behavior analysis rather than vendor-provided signatures.
Acronis has not said whether it plans to release more technical information later, but its stated intent is to give administrators time to patch first. For now, the most reliable protection is the available update. The incident also highlights the importance of keeping third-party control panel extensions current, as they often operate with high privileges and can become a path for attackers seeking to expand their access on a compromised server.
Sources
- BleepingComputer Original source
- brief advisory Also reporting
- advisory warns Also reporting
Continue Reading
Boards Want Proof Controls Work Now
A CISO argues that point-in-time audits no longer satisfy boards, regulators, and customers who want live proof that security controls are functioning.
LiteSpeed Enterprise Flaw Risks Root on Shared Hosts
cPanel warns a LiteSpeed Web Server Enterprise bug could let one hosting account gain root on shared servers, with no CVE assigned.
Homebrew 7.0.0 adds built-in vuln scanner
Homebrew 7.0.0 ships a native GUI, a Homebrew-specific advisory database, and stronger sandboxing as attackers keep targeting the package manager.