A high-severity Linux local privilege escalation vulnerability, assigned CVE-2026-87886 with a CVSS score of 7.8, has been disclosed in Acronis' backup plugin for cPanel, WebHost Manager (WHM), and Plesk. This flaw allows an attacker to increase their permission level on a vulnerable server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction. The vulnerability affects versions of the plugin prior to 1.9.3.1021 for cPanel & WHM and prior to 1.8.11.638 for Plesk, with fixed versions available in 1.9.3 HF3 and 1.8.11 respectively. Acronis has detected exploitation of this vulnerability in the wild, in limited, targeted attacks against its backup plugin for cPanel & WHM deployments, which may indicate an increased risk to business operations if left unpatched. Affected users are recommended to apply available updates immediately to prevent potential disruptions and data breaches, highlighting the importance of timely patching to maintain system security and integrity.
The following reports contain further technical details:[/subscribe_to_unlock_form]
A high-severity Linux local privilege escalation vulnerability, assigned CVE-2026-87886 with a CVSS score of 7.8, has been disclosed in Acronis' backup plugin for cPanel, WebHost Manager (WHM), and Plesk. This flaw allows an attacker to increase their permission level on a vulnerable server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction. The vulnerability affects versions of the plugin prior to 1.9.3.1021 for cPanel & WHM and prior to 1.8.11.638 for Plesk, with fixed versions available in 1.9.3 HF3 and 1.8.11 respectively. Acronis has detected exploitation of this vulnerability in the wild, in limited, targeted attacks against its backup plugin for cPanel & WHM deployments, which may indicate an increased risk to business operations if left unpatched. Affected users are recommended to apply available updates immediately to prevent potential disruptions and data breaches, highlighting the importance of timely patching to maintain system security and integrity.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]