Acronis disclosed CVE-2026-87886, a high severity local privilege escalation vulnerability caused by insecure file permissions in its Backup plugin for cPanel and WHM and its Backup extension for Plesk, and confirmed the flaw has already been exploited in the wild in limited, targeted attacks. The vulnerability, rated 7.8 on the CVSS scale, lets a low privileged attacker who already has some foothold on a Linux server raise their permission level, potentially reaching sensitive backup data or disrupting the system without needing the user to click or approve anything. Acronis fixed the issue in Backup plugin for cPanel and WHM build 1.9.3.1021 (hotfix 3) and Backup extension for Plesk build 1.8.11.638, and is withholding further technical detail to give administrators time to patch before more becomes public.
For hosting providers and the businesses that depend on shared cPanel and Plesk infrastructure, a backup plugin is an unusually sensitive place for a privilege escalation bug to live: it typically runs with elevated access to move and restore data across the entire server, which is exactly the kind of standing privilege a local attacker wants to hijack rather than fight. That combination is consistent with the pattern CyberTech has tracked in this year’s wave of infrastructure tooling flaws under active exploitation weeks after disclosure.
The original insight is what Acronis chose not to say. By withholding exploitation detail while confirming in the wild attacks, Acronis is betting that limited disclosure slows attacker replication faster than it slows defender patching, the same tradeoff GitLab made with its own critical flaw this month. Administrators running either plugin should treat the build number, not the missing technical writeup, as the actionable signal.
Source: Acronis Advisory Database