---
schema: 1
kind: vulnerability
title: "CVE-2026-87886 — Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)"
headline: "Acronis's own hosting-panel backup plugin let a low-privilege local user escalate — CISA lists it as exploited on a single customer's report"
summary: >
  CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file
  permissions in the Acronis Backup plugin for cPanel & WHM and extension for Plesk; CISA added
  it to the KEV catalog on 2026-09-16 based on Acronis's own report of one potentially-affected
  customer, and fixed builds are available for both products.
discovered_at: "2026-09-18T04:52:00Z"
updated_at: null
event_date: "2026-09-16"
run_id: 2026-09-18T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, priv-esc, cisa-kev, patch-available]
regions: [global]
sectors: [technology]
entities: []
techniques: [T1068]
affected_products: ["Acronis Backup plugin for cPanel & WHM (Linux)", "Acronis Backup extension for Plesk (Linux)"]
cves:
  - id: CVE-2026-87886
    cvss: "7.8"
    epss: null
    type: priv-esc
    vector: local
    auth: post-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021; extension for Plesk before build 1.8.11.638 (both Linux)"
    fixed: "cPanel & WHM plugin 1.9.3 HF3 (build 1.9.3.1021); Plesk extension build 1.8.11.638"
sources:
  - url: "https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/"
    publisher: "Help Net Security"
    date: "2026-09-16"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/"
    publisher: "BleepingComputer"
    date: "2026-09-15"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities Catalog (JSON feed)"
    date: "2026-09-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments"
    publisher: "Acronis (via BleepingComputer)"
    source_url: "https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/"
  - quote: "the assessment is based on a single report from a 'potentially affected' customer"
    publisher: "BleepingComputer"
    source_url: "https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/"
verification: multi-source
sourcing_note: >
  Acronis's own advisory page (security-advisory.acronis.com/advisories/SEC-10986) is a
  client-side-rendered application returning no readable content on any transport tried; every
  vulnerability-description fact is cited to Help Net Security and BleepingComputer, both of
  which quote Acronis's advisory text directly, plus CISA's KEV catalog for the listing itself.
  Acronis attributes its exploitation assessment to a single customer's report of being
  potentially affected, not a broadly observed campaign, and has published no indicators.
confidence: medium
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Update the Acronis Backup plugin/extension on every cPanel & WHM (<1.9.3.1021) or Plesk (<1.8.11.638) server to the fixed build now, regardless of the single-customer-report basis behind Acronis's exploitation claim."
updates: []
migrated_from: null
---

CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file permissions (CWE-276) in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, both on Linux ([Help Net Security, 2026-09-16](https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/)). A local attacker who already holds low-privilege access on an affected hosting-panel server can escalate to elevated privileges by abusing the plugin's own file permissions; no remote or unauthenticated path is described. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline, and Acronis's advisory, quoted by both Help Net Security and BleepingComputer, states exploitation has been detected "in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments" ([BleepingComputer, 2026-09-15](https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/)) — Acronis itself told BleepingComputer that assessment rests on a single report from a "potentially affected" customer, not a broadly observed campaign, and has published no indicators. Help Net Security states there are currently no signs of active exploitation on Plesk deployments specifically, so the confirmed activity is limited to the cPanel & WHM plugin ([Help Net Security, 2026-09-16](https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/)). Fixed builds: cPanel & WHM plugin 1.9.3 HF3 (build 1.9.3.1021), Plesk extension build 1.8.11.638.

**Defender takeaway:** update the Acronis Backup plugin or extension on every cPanel & WHM or Plesk server to the fixed build now regardless of the single-customer-report basis behind Acronis's exploitation claim; CISA's KEV listing reflects its own independent judgment that active exploitation occurred.
