Acronis Warns of Actively Exploited Linux Privilege Escalation Flaw in cPanel Backup Plugin
Acronis has disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugins for cPanel, WebHost Manager (WHM), and Plesk, warning that the flaw is being exploited in the wild.
Tracked as CVE-2026-87886, the vulnerability has a severity score of 7.8. It affects backup integrations used by web hosting companies and server administrators to manage websites and servers through graphical control panels.
Acronis Backup connects hosting control panels to an organization’s infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces.
In a security update issued today, Acronis identified the flaw as CVE-2026-87886 and rated it high severity.
A low-privileged attacker could exploit CVE-2026-87886 to elevate privileges on a vulnerable Linux server, access or modify sensitive data, and potentially disrupt the system without user interaction.
Acronis is withholding additional technical details to give system administrators time to apply the available patches before releasing more information.
Acronis says the vulnerability is being exploited
Acronis said it detected CVE-2026-87886 being exploited in the wild as part of a “limited targeted attack.”
“Exploitation of this vulnerability has been detected in the wild as a limited targeted attack against the Acronis Backup plugin for cPanel and WHM deployments,” the company warned in its advisory.
In a statement to BleepingComputer, Acronis said the assessment was based on a single report from a “potentially affected” customer.
The company did not identify specific indicators of compromise. It also did not disclose when the activity occurred or what attackers accomplished beyond the privilege escalation described in the advisory.
Acronis Backup versions affected by CVE-2026-87886
- Acronis Backup plugin for cPanel and WHM: Builds before 1.9.3.1021; fixed in version 1.9.3 HF3.
- Acronis Backup Extension for Plesk: Builds earlier than 1.8.11.638; fixed in version 1.8.11.
All users of the Acronis Backup integrations for cPanel, WHM, and Plesk are encouraged to apply the available updates immediately.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



