Acronis Fixes Flaw in cPanel and Plesk Plugins, Reports Limited Exploitation

CVE-2026-87886 enables local privilege escalation in Acronis Backup Linux plugins for cPanel & WHM and Plesk. Fixed versions are available.

Acronis CVE-2026-87886 is a vulnerability in the Linux backup plugins for the cPanel & WHM and Plesk administration panels. The manufacturer has fixed it and said it observed limited targeted exploitation against deployments of the Acronis Backup plugin for cPanel & WHM.

The flaw has a CVSS score of 7.8 out of 10 and is related to insecure file permissions. A local attacker with low privileges could therefore elevate their privileges on a vulnerable Linux server. This is not a flaw that can be exploited directly remotely without prior access to the server.

Acronis CVE-2026-87886: Affected Versions and Fixes

The following releases are affected:

  • Acronis Backup plugin for cPanel & WHM in builds older than 1.9.3.1021,
  • Acronis Backup extension for Plesk in versions older than 1.8.11.638.

Acronis released fixes in Acronis Backup plugin for cPanel & WHM 1.9.3 HF3 and Acronis Backup extension for Plesk 1.8.11. Server administrators are advised to update both plugins without delay.

Why the Flaw Affects Hosting Servers

Acronis plugins are integrated into administration panels used by hosting companies and administrators to back up and restore websites, databases, mailboxes, and hosting accounts. After gaining low-privilege access, an attacker could exploit the flaw to expand their access rights.

According to Acronis, exploitation was observed in limited targeted attacks against the cPanel & WHM plugin. However, the company did not disclose technical details of the attacks, when they occurred, indicators of compromise, or confirmed consequences for specific customers.

Acronis’s statement to BleepingComputer also suggests that the information about active exploitation is based on a single report from a potentially affected customer. Widespread exploitation has not been confirmed, nor have attacks against the Plesk plugin.

What Administrators Should Do

Operators should first verify the installed plugin versions and deploy the available fixed releases. When investigating a possible incident, they should consider that the manufacturer has not yet provided public indicators of compromise.

Further information may come from a possible technical update to the Acronis advisory, independent data on the scope of the attacks, or the addition of CVE-2026-87886 to the CISA Known Exploited Vulnerabilities catalog.

Sources

  • Acronis Advisory Database — SEC-10986 – Acronis’s primary notice on CVE-2026-87886, affected versions, fixed releases, and limited targeted exploitation.
  • Vulners — ACRONIS:SEC-10986 – Mirrors Acronis advisory data, including the publication time, CVSS 7.8, affected version ranges, and the claim of limited targeted attacks.
  • BleepingComputer – Adds Acronis’s statement that the active-exploitation assessment is based on a single report from a potentially affected customer and that no indicators of compromise were disclosed.

Verified and updated: 09/16/2026 06:21

Sharing