Acronis Warns of Actively Exploited Privilege Escalation Flaw in cPanel and Plesk Backup Plugins
**Acronis** has issued a critical warning regarding a high-severity Linux local privilege escalation vulnerability, tracked as **CVE-2026-87886**, affecting its backup plugins for **cPanel & WHM** and **Plesk**. The flaw, with a CVSS score of 7.8, is reportedly being actively exploited in limited, targeted attacks, allowing low-privileged attackers to elevate their permissions on vulnerable servers. System administrators are urged to apply available patches immediately to mitigate the risk.
Cloud data management company **Acronis** has disclosed a significant security vulnerability in its backup plugins for popular web hosting control panels, **cPanel & WHM** and **Plesk**. The flaw, identified as **CVE-2026-87886**, is a high-severity Linux local privilege escalation issue that could allow attackers to gain elevated access.
### The Vulnerability Explained
**CVE-2026-87886** allows a low-privileged attacker to escalate their permissions on a vulnerable Linux server. This could grant them unauthorized access to sensitive data, enable system modifications, or cause disruptions without requiring user interaction.
While **Acronis** has confirmed active exploitation in the wild, specific technical details about the vulnerability remain undisclosed. This strategic decision aims to provide system administrators with sufficient time to apply patches before broader knowledge of the exploit could lead to more widespread attacks.
### Impact and Exploitation
**Acronis** stated that exploitation of **CVE-2026-87886** has been detected in "limited, targeted attacks" against deployments of the **Acronis Backup plugin for cPanel & WHM**. The company's assessment is based on a single report from a potentially affected customer.
Though specific indicators of compromise (IoCs) have not been released, and details regarding the timeline or the full extent of successful attacks are scarce, the privilege escalation capability alone poses a substantial risk to server integrity and data security.
### Affected Versions and Patches
The vulnerability impacts the following product versions:
* **Acronis Backup plugin for cPanel & WHM** builds earlier than 1.9.3.1021. This issue is resolved in version 1.9.3 HF3.
* **Acronis Backup extension for Plesk** builds earlier than 1.8.11.638. This issue is resolved in version 1.8.11.
Administrators utilizing these **Acronis** backup integrations are strongly advised to update their systems immediately to the patched versions. Failure to do so could leave their servers exposed to ongoing attacks.
