LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 16, 2026
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)
7.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 19, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on Sep 16, 2026, with a federal patch deadline of Sep 19, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

CVE-2026-87886 is an incorrect default permissions issue in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Weak file or directory permissions can let a lower-privileged user gain higher privileges on the host. For teams running shared hosting control panels, that matters because backup components often touch sensitive configuration, credentials, and restore paths; privilege escalation there can expand an attacker’s reach across customer accounts and infrastructure. Confirm exact product builds, fixed releases, and deployment notes against the vendor advisory before you act.

CISA describes the weakness as incorrect default permissions that could allow privilege escalation. Known ransomware use is not documented in the provided facts. Treat this as a high-priority configuration and access-control defect on systems that host those plugins or extensions, and follow vendor instructions together with applicable CISA BOD 26-04 guidance for prioritization and exposure review.

How it works

This vulnerability is classed as CWE-276 (Incorrect Default Permissions). In this class, installers or packages leave files, directories, or related objects with permissions that are too broad—for example, writable or executable by users who should only have limited rights. An attacker who already has a foothold as a less-privileged user (or who can run code in a constrained context on the same host) may read, modify, or replace protected material, or influence processes that run with higher rights, and thereby escalate privileges.

Public detail in the given facts does not describe exact paths, permission bits, or step-by-step abuse. Do not assume a particular exploit chain. In practice for backup plugins and control-panel extensions, defenders should assume that overly permissive defaults on plugin/extension files, service wrappers, or data directories are the abuse surface, and verify the real layout and ownership model only from vendor documentation and your own hosts.

Am I affected? How to find it in your systems

You are in scope if you run Acronis Backup integrated as a plugin for cPanel & WHM or as an extension for Plesk. These components typically live on Linux hosting servers that provide multi-tenant control panels, often with internet-facing management interfaces and scheduled backup jobs.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation package for the Acronis Backup plugin for cPanel & WHM and the extension for Plesk exactly as the vendor advisory instructs. Validate installation success on a pilot host, then roll out across the estate. After updating, re-check file and directory permissions and ownership against vendor guidance so defaults are not left overly permissive.

If you can't patch immediately

Reduce blast radius until the vendor fix is applied. Compensating controls for incorrect default permissions and local privilege escalation on control-panel hosts include:

Reassess internet exposure daily for unpatched assets and treat externally reachable panel hosts as higher urgency under BOD 26-04-style risk prioritization.

If your data may have been exposed

Actively exploited privilege-escalation flaws on backup and hosting infrastructure can lead to broader compromise and data exposure, even when ransomware use is not documented for this CVE. If you suspect abuse, isolate affected hosts, preserve volatile evidence and logs, rotate credentials that backup or panel software could access, and follow your incident response plan including any CISA forensics triage requirements that apply to your organization. As a simple personal check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their identities already appear in public breach material, then proceed with organizational investigation and recovery as needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAcronis · Backup
WeaknessCWE-276
CVSS base score7.8 (High)
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedSep 17, 2026
Added to CISA KEVSep 16, 2026
Federal patch deadlineSep 19, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities