CVE-2025-24832: Acronis Backup Extension For Plesk

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.

Affected products

  • Acronis Acronis Backup Extension For Plesk: before 1.8.7.615 (fixed in 1.8.7.615)
  • Acronis Acronis Backup Plugin For cPanel & WHM: before 1.8.4.866 (fixed in 1.8.4.866); before 1.9.1.892 (fixed in 1.9.1.892)

Published 2025-02-27. Last modified 2026-06-17.