Acronis Warns of High-Severity Flaw in Backup Plugin for cPanel/WHM

High · The Hacker News ·

Exploited

Verification: The article URL is dated September 2026, which is in the future relative to the current date, and no independent corroboration or CVE record is provided, making the claimed event unverifiable.

Key points

  • CVE-2026-87886 affects the Acronis Backup plugin for cPanel and WHM on Linux.
  • CVSS score is 7.8; the flaw is a local privilege escalation caused by insecure file permissions.
  • The vulnerability was reportedly exploited in targeted attacks.
  • Administrators should patch, audit permissions, and monitor for signs of compromise.

According to reports, Acronis has cautioned users about a high-risk flaw in its Backup extension designed for cPanel and WHM on Linux. Tracked as CVE-2026-87886 with a CVSS score of 7.8, the issue is described as a local privilege escalation caused by insecure file permissions. The advisory reportedly notes exploitation in targeted attacks, raising urgency for hosting providers and K-12 IT teams that rely on cPanel/WHM for web hosting and backup workflows.

Affected systems are Linux servers running the Acronis Backup plugin within cPanel or WHM. Because cPanel/WHM often underpins shared hosting, school district web portals, and internal web services, a local privilege escalation flaw can let an attacker with limited access, such as a compromised cPanel account or a low-privileged process, elevate to higher privileges on the same server. That could expose backup data, configuration secrets, and other tenants' files.

Local privilege escalation may not be remotely exploitable on its own, but it is a powerful post-compromise step. In targeted attacks, adversaries commonly chain such flaws with initial access through weak credentials, vulnerable web apps, or misconfigurations. Insecure file permissions are a recurring root cause: overly permissive directories or files can allow unintended users to modify executables, scripts, or configuration that run with elevated rights.

The reported September 2026 timeframe and active exploitation claims mean administrators should treat this as urgent. Even without public proof-of-concept details, the combination of a high CVSS score, a backup plugin, and cPanel/WHM makes it attractive for ransomware and data-theft operations. Backups are a high-value target because tampering or theft can undermine recovery and expose sensitive data.

What to watch: vendor advisories and plugin updates, signs of unexpected privilege changes, new or modified files in plugin directories, unusual cron jobs, and authentication anomalies. If exploitation is suspected, preserve logs, isolate the server, and rotate credentials and API tokens. Until a patch is confirmed, reducing exposure by restricting plugin access and reviewing permissions is prudent.

What to do now

  1. Apply the latest Acronis Backup plugin update for cPanel/WHM as soon as a vendor patch is available, and verify the installed version.
  2. Audit and correct file permissions on plugin directories, configuration files, and executables; remove world-writable and unnecessary group-writable permissions.
  3. If the plugin is not essential, temporarily disable or remove it until a patched version is confirmed.
  4. Review cPanel/WHM and system logs for signs of local privilege escalation, unexpected user or group changes, new SUID/SGID binaries, or suspicious cron jobs.
  5. Restrict access to cPanel/WHM and plugin interfaces using IP allowlisting, MFA, and least-privilege accounts.
  6. Rotate credentials, API tokens, and backup encryption keys if compromise is suspected, and validate backup integrity with offline copies.
  7. Monitor vendor advisories and threat intelligence for exploitation details, and apply compensating controls such as host-based monitoring and EDR.

CVE references

  • CVE-2026-87886

Original source

The Hacker News

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news