ZeroDayAlert

CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Acronis Backup Added to KEV 2026-09-16 Federal due 2026-09-19 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Acronis Backup when deployed as a plugin for cPanel & WHM or as an extension for Plesk. The defect is an incorrect default permissions setting that could allow privilege escalation on affected systems. The record does not specify which versions of Acronis Backup, cPanel, WHM, or Plesk are affected, nor does it detail the scope of the permissions misconfiguration.

How to check whether this touches you

  • Inventory whether you run cPanel & WHM or Plesk with Acronis Backup installed as an add-on component.
  • Confirm whether any such systems are reachable from the internet or from untrusted network segments; systems isolated to trusted administrator networks carry lower risk.
  • Review the default file and directory permissions on the Acronis Backup plugin installation directory (typically under /usr/local/cpanel/ for cPanel or /usr/local/psa/ for Plesk) to identify whether the umask or ACLs grant write access to unprivileged accounts.
  • Cross-check your installed Acronis Backup version against vendor release notes; note that backported security fixes may exist in patch releases not widely advertised.

What to do

  1. Contact Acronis Support and request the vendor's specific mitigation steps for your version and control panel, since the record does not cite a patch version.
  2. Until mitigation is applied, restrict network access to the affected cPanel/WHM or Plesk instance to trusted administrator IP ranges only, and disable remote access protocols (SSH, HTTPS admin panel) if not required.
  3. Enable detailed logging of file permission changes and privileged account activity on the affected systems; configure log aggregation to a remote syslog server if available.
  4. If mitigations are unavailable for your version, escalate to your change management process and business owner to decide whether to discontinue use of Acronis Backup in that environment.
  5. Document the date of remediation or discontinuation and retain evidence of compliance with BOD 26-04 timelines for your federal or contractual reporting obligations.

If you find you were exposed

Review access logs and file modification timestamps on the affected systems for the period prior to discovery, focusing on activity by non-root users in the Acronis Backup plugin directories and any unexpected privilege escalation attempts. Exploitation of permission vulnerabilities often precedes public disclosure, so logs older than your current retention window may be unavailable; prioritise preservation of existing audit trails and consider engaging a forensics team if you detect signs of lateral movement or credential theft.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-87886 is being exploited. It cannot tell you whether Backup is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →