Skip to finding
important · Privilege

Attackers are exploiting Acronis hosting-plugin permissions to elevate a local hosting account to root.

Affects

Acronis Backup integrations for cPanel/WHM, Plesk and DirectAdmin on Linux hosting servers.

A low-privilege user on an affected hosting server can alter a file or path later consumed by the privileged backup service.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026