CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2026-09-16. EPSS: 0.2% chance of exploitation in the next 30 days.
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Affected products
- Acronis Acronis Backup: before 1.2.3 (fixed in 1.2.3); before 1.8.11 (fixed in 1.8.11); before 1.9.3 (fixed in 1.9.3); version 1.9.3 only
Published 2026-09-17. Last modified 2026-09-18.