Skip to content
Tech News
← Back to articles

Acronis warns of actively exploited flaw in its cPanel backup plugin

read original more articles
Why This Matters

Acronis has disclosed a high-severity local privilege escalation flaw (CVE-2026-87886) in its backup plugin for cPanel/WHM and Plesk that is reportedly being exploited in the wild in limited, targeted attacks. Because these control panels are widely used by web hosting providers, an unpatched vulnerability like this could let low-privileged attackers gain elevated access on shared or managed servers, posing risk to hosting providers and their customers alike.

Key Takeaways

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.

cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces.

Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces.

The flaw was published in a brief advisory last weekend, but the technology company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8.

A low-privileged attacker can exploit CVE-2026-87886 to increase their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction.

Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information.

Acronis says it has detected exploitation of the vulnerability in the wild, "in limited, targeted attacks."

“Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns.

In a statement for BleepingComputer, Acronis notes that the assessment is based on a single report from a "potentially affected" customer.

The CVE-2026-87886 vulnerability affects the following product versions:

... continue reading