CISA Adds Acronis Backup cPanel/Plesk Permission Flaw to KEV
Moyen · CISA Known Exploited Vulnerabilities ·
En bref
- CISA KEV lists Acronis Backup plugin for cPanel & WHM and extension for Plesk.
- The flaw is incorrect default permissions and may allow privilege escalation.
- Required action: apply vendor mitigations and follow BOD 26-04 risk-based patching.
- If mitigations are unavailable for cloud services, discontinue use.
- Verify exposure and CVE details via the provided NVD link.
CISA's Known Exploited Vulnerabilities catalog has an entry for Acronis Backup components used with cPanel & WHM and Plesk. The issue is an incorrect default permissions vulnerability that could allow privilege escalation. The provided NVD URL points to CVE-2026-87886, but the CVE field was not included in the source metadata, so administrators should confirm the exact identifier and affected versions with Acronis and NVD.
Affected organizations are those running the Acronis Backup plugin for cPanel & WHM or the extension for Plesk, especially hosting providers and K-12 districts with web hosting or backup management on those platforms. Because these tools often run with elevated service permissions, a default permissions mistake can turn a low-privilege foothold into broader control over backup data or the hosting control panel.
Backup infrastructure is high-value. If an attacker can escalate privileges through a backup plugin, they may reach sensitive data, alter backups, or disrupt recovery. CISA's required action is to apply mitigations per vendor instructions and follow BOD 26-04 for risk-based security updates. For cloud services, if mitigations are unavailable, CISA guidance says to discontinue use.
CISA KEV entries indicate known exploitation, so this should not be treated as theoretical. The current classification is medium, but priority should be driven by internet exposure, asset criticality, and whether the plugin is reachable by untrusted users. Stakeholders must evaluate each asset's exposure and adhere to BOD 26-04 patching guidelines.
What to watch: the Acronis vendor advisory for fixed versions or configuration changes, the NVD entry for CVE-2026-87886, and any updates to the KEV entry. Confirm whether the plugin is installed, whether default permissions remain, and whether compensating controls exist. If no mitigation is available for a cloud-hosted instance, plan to discontinue use.
À faire maintenant
- Inventory all cPanel & WHM and Plesk systems with the Acronis Backup plugin or extension installed.
- Apply vendor mitigations or updates immediately; if none are available, remove or disable the plugin or extension.
- Review and correct default permissions on Acronis Backup files, directories, services, and configuration.
- Restrict access to cPanel, Plesk, and backup interfaces to trusted networks or VPN, and enforce MFA.
- Follow BOD 26-04 risk-based patching, prioritizing internet-exposed and high-value backup assets.
- For cloud services without mitigations, discontinue use per CISA guidance.
- Monitor logs for privilege escalation attempts and verify backup integrity and recovery capability.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.