Acronis cPanel/WHM Backup Plugin Flaw Exploited, Patch Urged
Élevé · The Hacker News ·
Exploité
En bref
- CVE-2026-87886 is a high-severity local privilege escalation flaw in Acronis Backup plugin for cPanel and WHM.
- The issue is caused by insecure file permissions and has a CVSS score of 7.8.
- Acronis says the vulnerability has been exploited in the wild in targeted attacks.
- Linux deployments of the plugin are affected; exact fixed versions should be confirmed in the vendor advisory.
Acronis has warned that a high-severity vulnerability in its Backup plugin for cPanel and Web Host Manager deployments has been exploited in real attacks. The flaw is tracked as CVE-2026-87886 and carries a CVSS score of 7.8. According to the available information, it is a local privilege escalation issue caused by insecure file permissions. The affected product is the Linux version of the Acronis Backup plugin for cPanel and WHM, though the precise version range should be verified against the vendor advisory.
cPanel and WHM are widely used control panels for Linux web hosting. A backup plugin in that environment typically runs with enough privilege to create, manage, and restore backups, which may include website files, databases, configuration data, and credentials. If an attacker already has a low-privileged foothold on the same system, weak file permissions could let them elevate their access, tamper with backups, or reach data belonging to other accounts. The fact that exploitation has been observed in targeted attacks suggests the flaw is not merely theoretical.
For K-12 organizations, the direct risk depends on whether the district self-hosts cPanel or WHM or relies on a service provider that does. Even when schools do not run the panel themselves, third-party hosting providers may use it for district websites, portals, or email services. A compromised backup plugin can undermine recovery plans, expose sensitive information, or give attackers a durable position inside a hosting environment. Because this is a local privilege escalation issue, it is often most dangerous after an initial compromise, making detection and containment especially important.
Administrators should watch for the vendor's patched release, any exploitation indicators, unexpected administrative accounts, changed backup jobs, and altered file permissions. Patching should be prioritized for internet-facing or shared hosting systems. If the plugin is not needed, removing or disabling it reduces exposure. Backup integrity should also be validated, since attackers who reach backup infrastructure may try to delete, encrypt, or alter recovery points.
À faire maintenant
- Inventory all cPanel and WHM systems running the Acronis Backup plugin and confirm the installed version against the vendor advisory.
- Apply the vendor-provided patch or update immediately, prioritizing internet-facing and shared hosting environments.
- If a patch is not yet available, disable or remove the plugin where possible and restrict local access to trusted administrators.
- Audit file permissions on plugin installation directories and backup storage, removing unnecessary world-writable or group-writable access.
- Review authentication, system, and plugin logs for signs of privilege escalation, unexpected admin activity, or backup job changes.
- Rotate credentials, API tokens, and secrets that may have been accessible from the affected host or backup configuration.
- Verify backup integrity and retention, and isolate or rebuild any system suspected of compromise before restoring services.
Références CVE
- CVE-2026-87886
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.