CVE-2024-34014: Acronis Backup Extension For Plesk
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.
Affected products
- Acronis Acronis Backup Extension For Plesk: before 1.8.6.599 (fixed in 1.8.6.599)
- Acronis Acronis Backup Plugin For cPanel & WHM: before 1.8.3.818 (fixed in 1.8.3.818); before 1.9.1.892 (fixed in 1.9.1.892)
- Acronis Acronis Backup Plugin For Directadmin: before 1.2.2.181 (fixed in 1.2.2.181)
Published 2024-11-11. Last modified 2026-06-17.