CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
CVE-2026-87886 is an incorrect default permissions issue in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Weak file or directory permissions can let a lower-privileged user gain higher privileges on the host. For teams running shared hosting control panels, that matters because backup components often touch sensitive configuration, credentials, and restore paths; privilege escalation there can expand an attacker’s reach across customer accounts and infrastructure. Confirm exact product builds, fixed releases, and deployment notes against the vendor advisory before you act.
CISA describes the weakness as incorrect default permissions that could allow privilege escalation. Known ransomware use is not documented in the provided facts. Treat this as a high-priority configuration and access-control defect on systems that host those plugins or extensions, and follow vendor instructions together with applicable CISA BOD 26-04 guidance for prioritization and exposure review.
How it works
This vulnerability is classed as CWE-276 (Incorrect Default Permissions). In this class, installers or packages leave files, directories, or related objects with permissions that are too broad—for example, writable or executable by users who should only have limited rights. An attacker who already has a foothold as a less-privileged user (or who can run code in a constrained context on the same host) may read, modify, or replace protected material, or influence processes that run with higher rights, and thereby escalate privileges.
Public detail in the given facts does not describe exact paths, permission bits, or step-by-step abuse. Do not assume a particular exploit chain. In practice for backup plugins and control-panel extensions, defenders should assume that overly permissive defaults on plugin/extension files, service wrappers, or data directories are the abuse surface, and verify the real layout and ownership model only from vendor documentation and your own hosts.
Am I affected? How to find it in your systems
You are in scope if you run Acronis Backup integrated as a plugin for cPanel & WHM or as an extension for Plesk. These components typically live on Linux hosting servers that provide multi-tenant control panels, often with internet-facing management interfaces and scheduled backup jobs.
- Inventory: List all cPanel/WHM and Plesk hosts. Record whether the Acronis Backup plugin or extension is installed, enabled, and which package or build is present. Use your CMDB, package managers, panel plugin lists, and configuration-management inventory—not assumptions from marketing names alone.
- Versions and configuration: Compare installed builds to the fixed releases named in the vendor advisory. Confirm default permission and ownership settings the vendor documents for plugin/extension paths. Specifics must be confirmed against the vendor advisory; do not rely on guessed version numbers.
- Exposure: Note which of these hosts are internet-reachable for panel, API, or backup-related services, and which accounts can log on locally or via the panel. CISA expects stakeholders to evaluate each asset’s internet exposure when applying BOD 26-04-style prioritization.
- Telemetry and logs: Watch for unexpected permission or ownership changes under plugin/extension directories, unusual process elevation tied to backup or panel users, failed or anomalous privilege-related operations, and new or modified binaries/scripts in backup component paths. Baseline normal backup job behavior so deviations stand out. Absence of known public exploit detail does not mean absence of risk if an attacker already has local access.
How to remediate
Patch first. Apply the vendor-supplied update or mitigation package for the Acronis Backup plugin for cPanel & WHM and the extension for Plesk exactly as the vendor advisory instructs. Validate installation success on a pilot host, then roll out across the estate. After updating, re-check file and directory permissions and ownership against vendor guidance so defaults are not left overly permissive.
- Remove or disable unused Acronis Backup panel integrations.
- Enforce least privilege on service accounts used for backup and panel plugins; avoid shared admin credentials.
- Restrict who can install or reconfigure panel plugins and extensions.
- Ensure backup data and config stores are not world-writable and are readable only by required roles.
- Document residual risk and schedule verification scans after change windows.
- Align prioritization and any cloud-hosted variants with CISA’s BOD 26-04 guidance and forensics triage expectations referenced in the CISA action notes; if mitigations are unavailable, discontinue use as directed in that guidance.
If you can't patch immediately
Reduce blast radius until the vendor fix is applied. Compensating controls for incorrect default permissions and local privilege escalation on control-panel hosts include:
- Segmentation: Isolate panel/backup servers from general user workloads and from high-value identity and domain systems; limit lateral paths.
- Access tightening: Reduce local interactive logons, lock down SSH/RDP and panel admin access with strong auth, allowlists, and jump hosts; remove unnecessary sudo or equivalent rights.
- Feature disablement: If operationally acceptable, disable the affected Acronis Backup plugin or Plesk extension until it can be updated.
- Virtual patching / WAF: Where a web-facing management path exists, apply strict allowlists and WAF rules for panel URLs; this does not fix local permission flaws but can reduce remote foothold quality.
- Host hardening: Correct overly broad permissions on known plugin paths only when you can do so safely per vendor guidance; mis-fixing can break backups—prefer vendor-supported steps.
- Monitoring: Heighten alerting on permission changes, unexpected privilege use, and backup component integrity. Preserve logs for incident response consistent with CISA forensics triage expectations.
Reassess internet exposure daily for unpatched assets and treat externally reachable panel hosts as higher urgency under BOD 26-04-style risk prioritization.
If your data may have been exposed
Actively exploited privilege-escalation flaws on backup and hosting infrastructure can lead to broader compromise and data exposure, even when ransomware use is not documented for this CVE. If you suspect abuse, isolate affected hosts, preserve volatile evidence and logs, rotate credentials that backup or panel software could access, and follow your incident response plan including any CISA forensics triage requirements that apply to your organization. As a simple personal check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their identities already appear in public breach material, then proceed with organizational investigation and recovery as needed.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H