CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)
Acronis's own hosting-panel backup plugin let a low-privilege local user escalate; CISA lists it as exploited on a single customer's report
Defender actions
- Update the Acronis Backup plugin/extension on every cPanel & WHM (<1.9.3.1021) or Plesk (<1.8.11.638) server to the fixed build now, regardless of the single-customer-report basis behind Acronis's exploitation claim.
Analysis
CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file permissions (CWE-276) in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, both on Linux (Help Net Security, 2026-09-16). A local attacker who already holds low-privilege access on an affected hosting-panel server can escalate to elevated privileges by abusing the plugin's own file permissions; no remote or unauthenticated path is described. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline, and Acronis's advisory, quoted by both Help Net Security and BleepingComputer, states exploitation has been detected "in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments" (BleepingComputer, 2026-09-15); Acronis itself told BleepingComputer that assessment rests on a single report from a "potentially affected" customer, not a broadly observed campaign, and has published no indicators. Help Net Security states there are currently no signs of active exploitation on Plesk deployments specifically, so the confirmed activity is limited to the cPanel & WHM plugin (Help Net Security, 2026-09-16). Fixed builds: cPanel & WHM plugin 1.9.3 HF3 (build 1.9.3.1021), Plesk extension build 1.8.11.638.
Cited evidence
Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments
the assessment is based on a single report from a 'potentially affected' customer
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.