important · Privilege
Attackers are exploiting Acronis hosting-plugin permissions to elevate a local hosting account to root.
Affects
Acronis Backup integrations for cPanel/WHM, Plesk and DirectAdmin on Linux hosting servers.
A low-privilege user on an affected hosting server can alter a file or path later consumed by the privileged backup service.
Detail and 5 sources
Acronis identifies fixed releases, but the fix was not read for a Priority Finding.
Sources
ResearchCVE-2026-87886 - Vulnerability Details - OpenCVEResearchAcronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) - Help Net SecurityResearchAcronis: rilevato sfruttamento in rete della CVE-2026-87886 (AL09/260916/CSIRT-ITA) – CSIRT ToscanaVendorAcronis Advisory Database - AcronisCVEhttps://cve.org/CVERecord?id=CVE-2026-87886