Acronis Patches Exploited cPanel Backup Plugin Vulnerability

Acronis has fixed a high-severity flaw in its backup plugin for cPanel and WHM after targeted attacks exploited the issue. The bug can let a local user or process gain elevated permissions on Linux servers.
Acronis Patches Exploited cPanel Backup Plugin Vulnerability
Share

Acronis has patched a high-severity vulnerability in its Backup plugin for cPanel and Web Host Manager after attackers exploited the flaw in targeted attacks. The issue, tracked as CVE-2026-87886, affects Linux deployments and carries a CVSS severity score of 7.8.

The company said the defect had seen exploitation in the wild, as first reported by The Hacker News. Acronis did not characterize the attacks beyond describing them as targeted.

Insecure permissions can expose hosting server controls

The security bug stems from insecure file permissions in the backup extension. Successful exploitation can lead to local privilege escalation, which means an attacker who already controls a local account or process could increase the permissions available to them on the server.

cPanel and WHM help administrators manage web-hosting servers, including accounts and site operations. Elevated access on one of those systems can give an intruder a stronger position from which to interfere with hosted environments or pursue additional access, depending on the permissions obtained.

The risk is especially relevant for hosting providers and organizations that operate shared Linux infrastructure. A local foothold can carry more weight on a server that handles administration for several hosted customers, while backup software may hold access needed to read or write protected data.

Administrators should identify affected Linux installations

Organizations using the Acronis Backup plugin with cPanel or WHM should identify their Linux deployments and apply the vendor’s available remediation. Security teams should also review local accounts and processes with access to the server, since the reported weakness requires an established local position before permissions can be elevated.

Acronis has not disclosed the affected or fixed plugin versions. The company also has not reported how many systems or victims were impacted, how attackers gained their initial access, the technical mechanics of the incidents, or when exploitation and the patch release occurred.

This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.

MediaTek Dimensity 9600 Pro Uses TSMC’s 2nm for Premium Phones

MediaTek Dimensity 9600 Pro Uses TSMC’s 2nm for Premium Phones

Prev
Fable’s Xbox Importance Helped Sustain Long Reboot, Director Says

Fable’s Xbox Importance Helped Sustain Long Reboot, Director Says

Next