Skip to main content
QUIETLYTIC
Vulnerability

Acronis Backup plugin for cPanel & WHM Privilege Escalation (CVE-2026-87886)

CVE-2026-87886 is a CVSS 7.8 local privilege escalation in Acronis Backup control-panel plugins, confirmed exploited per CISA KEV.

CVE-2026-87886
Threat Level
HIGH
CVSS
7.8
Status
Active Exploitation
Confidence
High
Affected Products
Acronis Backup plugin for cPanel & WHM (before 1.9.3.1021), Acronis Backup extension for Plesk (before 1.8.11.638), Acronis Backup plugin for DirectAdmin (before 1.2.3.238)

CVE-2026-87886 carries a CVSS 3.0 base score of 7.8 against Acronis Backup’s plugins for three hosting control panels: cPanel & WHM, Plesk, and DirectAdmin, all on Linux. NVD, CISA’s own KEV entry, and VulnCheck’s KEV feed all independently classify it as CWE-276 (Incorrect Default Permissions). CISA added this CVE to its Known Exploited Vulnerabilities catalog on September 16, 2026, confirming real-world exploitation directly rather than through a single vendor report; VulnCheck’s KEV feed independently corroborates the same exploitation status and date.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD’s description states this is a local privilege escalation vulnerability caused by insecure file permissions, affecting the Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021, the Acronis Backup extension for Plesk before build 1.8.11.638, and the Acronis Backup plugin for DirectAdmin before build 1.2.3.238 — all Linux-hosted. NVD does not specify which files or directories carry the insecure permissions; Acronis’s own linked security advisory is the authoritative technical source, but our source data does not carry deeper mechanism detail from it.

Evidence and confidence

  • High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV, both dated September 16, 2026.
  • High confidence — the CWE-276 classification, independently corroborated across NVD, CISA KEV, and VulnCheck KEV.
  • Medium confidence — the CVSS 7.8 score and vector (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), which trace to NVD alone in our current ingestion.
  • Our source data does not carry an EPSS score or percentile for this CVE.

No field is in conflict between our sources.

Why this matters

This vulnerability requires local access to exploit (AV:L), which narrows its exposure relative to a fully remote flaw, but hosting control panels like cPanel, Plesk, and DirectAdmin are frequently multi-tenant environments where several customer accounts share the same underlying server — exactly the setting where a local privilege escalation flaw becomes most dangerous, since any tenant with ordinary account access could potentially leverage insecure file permissions to escalate beyond their intended privilege level. CISA’s confirmation of exploitation, corroborated independently by VulnCheck, means this should be treated as an active threat in shared-hosting environments running any of the three affected plugins, not a theoretical local-access edge case.

Frequently Asked Questions

What is CVE-2026-87886? A CVSS 7.8 local privilege escalation vulnerability (CWE-276) caused by insecure file permissions in Acronis Backup’s plugins for cPanel & WHM, Plesk, and DirectAdmin on Linux.

Is CVE-2026-87886 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog and VulnCheck’s KEV feed, both dated September 16, 2026.

Do I need remote network access to exploit this? No. The CVSS vector specifies a local attack vector, meaning the attacker needs some form of existing local access to the affected server — a meaningful consideration in shared-hosting/multi-tenant environments.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which versions fix this? Per NVD: Acronis Backup plugin for cPanel & WHM build 1.9.3.1021+, Acronis Backup extension for Plesk build 1.8.11.638+, and Acronis Backup plugin for DirectAdmin build 1.2.3.238+.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-87886. Exploitation status and the September 16, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. Acronis’s own advisory: Acronis Security Advisory SEC-10986. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 VulnCheck KEV

Related intelligence


Analyst tools