CVE-2020-35556: Acronis Cyber Protect

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.

Affected products

  • Acronis Cyber Protect: before 15 (fixed in 15); version 15 only

Published 2021-02-22. Last modified 2026-06-17.