CTIPilot

Acronis Backup extension for Plesk (Linux)

product · product:acronis-backup-extension-for-plesk-linux

Coverage timeline
1
first 2026-09-18 → last 2026-09-18
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Acronis Backup extension for Plesk (Linux)
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-18/cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev · ATT&CK page ↗

Story timeline

  1. 2026-09-18CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)
    trending-vulnerabilitiesAcronis's own hosting-panel backup plugin let a low-privilege local user escalate; CISA lists it as exploited on a single customer's report

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • bleepingcomputer.com1 (33%)
  • cisa.gov1 (33%)
  • helpnetsecurity.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Acronis Backup extension for Plesk (Linux) (1)

2026-09-18 · view entry permalink →

HIGHCVE-2026-87886exploitedNATOB2

CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)

CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file permissions (CWE-276) in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, both on Linux (Help Net Security, 2026-09-16). A local attacker who already holds low-privilege access on an affected hosting-panel server can escalate to elevated privileges by abusing the plugin's own file permissions; no remote or unauthenticated path is described. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline, and Acronis's advisory, quoted by both Help Net Security and BleepingComputer, states exploitation has been detected "in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments" (BleepingComputer, 2026-09-15); Acronis itself told BleepingComputer that assessment rests on a single report from a "potentially affected" customer, not a broadly observed campaign, and has published no indicators. Help Net Security states there are currently no signs of active exploitation on Plesk deployments specifically, so the confirmed activity is limited to the cPanel & WHM plugin (Help Net Security, 2026-09-16). Fixed builds: cPanel & WHM plugin 1.9.3 HF3 (build 1.9.3.1021), Plesk extension build 1.8.11.638.

Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments

Acronis (via BleepingComputer)

the assessment is based on a single report from a 'potentially affected' customer

BleepingComputer 2026-09-15
vulnerability18 Sep 04:52Zmulti-sourceOpen finding ↗