Acronis has disclosed a high-severity Linux local privilege-escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk. The company identifies the flaw as CVE-2026-87886 and assigns it a severity score of 7.8.
The plugin connects hosting control panels to Acronis infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts. cPanel & WHM and Plesk are used by web-hosting companies and server administrators to manage websites and servers through graphical interfaces.
A low-privileged attacker could exploit CVE-2026-87886 to increase their permissions on a vulnerable Linux server. The advisory says this could allow access to or modification of sensitive data and disruption of the system without user interaction.
Acronis says it has detected exploitation in the wild in limited, targeted attacks against Acronis Backup plugin deployments for cPanel & WHM. In a statement to BleepingComputer, the company said its assessment is based on a single report from a potentially affected customer.
Acronis has not published further technical details, specific indicators of compromise, the timing of the activity, or information about attacker results beyond the privilege-escalation impact described in the advisory. The advisory recommends that affected users apply the available updates immediately.
Comments
0No comments yet. Be the first to comment.