CVE-2022-3405: Acronis Cyber Backup

High severity, CVSS 8.8. EPSS: 5.3% chance of exploitation in the next 30 days.

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.

Affected products

  • Acronis Cyber Backup: version 12.5 only
  • Acronis Cyber Protect: version 15 only

Published 2023-05-03. Last modified 2026-06-17.