MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-15 · via BleepingComputer

Acronis patches privilege escalation bug in hosting control panel backup tools

Image via BleepingComputer
Image via BleepingComputer

Acronis has disclosed a high-severity local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk, tracked as CVE-2026-87886. The flaw allows low-privileged attackers to gain elevated permissions on Linux servers, potentially accessing or modifying sensitive data. Acronis reports limited targeted exploitation in the wild and recommends immediate updates to affected builds.

Expanded Detail

The vulnerability carries a CVSS severity score of 7.8 and can be exploited without user interaction. Acronis has withheld technical details to give administrators time to apply patches. The company's exploitation assessment rests on a single report from a potentially affected customer, and no indicators of compromise have been published. Fixed builds are available for both the cPanel & WHM plugin and the Plesk extension.

Backup plugins for hosting control panels operate with elevated system privileges, making them attractive targets for attackers seeking to escalate access on Linux servers. The targeted nature of the reported attacks suggests threat actors may be focusing on hosting providers, where compromising one server could expose data across multiple customer accounts.

Context

Hosting providers and server administrators are the primary parties affected by this vulnerability. A successful exploit could allow low-privileged users to gain elevated permissions, potentially exposing sensitive customer data stored on shared hosting servers. Because cPanel and Plesk manage multiple accounts on single systems, a compromise may affect numerous websites and databases at once. The limited targeted exploitation reported could indicate attackers are selectively probing hosting infrastructure, though the full scope remains unclear. Organizations relying on these plugins should assess their exposure promptly.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
CISA flags active exploitation of critical GitLab vulnerability · Cybersecurity
Critical WooCommerce plugin flaw exploited to upload backdoors · Cybersecurity
Cisco fixes actively exploited email gateway flaw allowing root access · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Acronis warns of actively exploited flaw in its cPanel backup plugin.” Browse more stories.