Acronis patches privilege escalation bug in hosting control panel backup tools

Acronis has disclosed a high-severity local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk, tracked as CVE-2026-87886. The flaw allows low-privileged attackers to gain elevated permissions on Linux servers, potentially accessing or modifying sensitive data. Acronis reports limited targeted exploitation in the wild and recommends immediate updates to affected builds.
The vulnerability carries a CVSS severity score of 7.8 and can be exploited without user interaction. Acronis has withheld technical details to give administrators time to apply patches. The company's exploitation assessment rests on a single report from a potentially affected customer, and no indicators of compromise have been published. Fixed builds are available for both the cPanel & WHM plugin and the Plesk extension.
Backup plugins for hosting control panels operate with elevated system privileges, making them attractive targets for attackers seeking to escalate access on Linux servers. The targeted nature of the reported attacks suggests threat actors may be focusing on hosting providers, where compromising one server could expose data across multiple customer accounts.
Hosting providers and server administrators are the primary parties affected by this vulnerability. A successful exploit could allow low-privileged users to gain elevated permissions, potentially exposing sensitive customer data stored on shared hosting servers. Because cPanel and Plesk manage multiple accounts on single systems, a compromise may affect numerous websites and databases at once. The limited targeted exploitation reported could indicate attackers are selectively probing hosting infrastructure, though the full scope remains unclear. Organizations relying on these plugins should assess their exposure promptly.