CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability

Summary

Acronis Backup and its plugins for cPanel & WHM and Plesk have an incorrect default permissions vulnerability. This flaw could allow for privilege escalation, and users are advised to apply mitigations as per vendor instructions or discontinue use if mitigations are unavailable.

IFF Assessment

FOE

The vulnerability allows for privilege escalation, which is a negative outcome for defenders.

Severity

8.8 High (AI Estimated)

This vulnerability allows for privilege escalation, potentially with a high impact on confidentiality, integrity, and availability. The attack vector is likely local or via a privileged account that can access the system where the plugin is installed.

CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating this vulnerability in Acronis Backup installations, especially in environments where privilege escalation could lead to significant compromise. The use of default permissions flaws highlights the ongoing importance of secure configuration management and regular security audits.

Read Full Story →