Home Β· Wiki Β· Vulnerabilities & CVEs
type: cve Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [cve, exploited, privilege-escalation] Β· confidence: medium Β· severity: high Β· affected_sectors: [global] Β· au_impact: false

A local privilege-escalation flaw in Acronis Backup caused by insecure file permissions. NVD records a score of 7.8 (High, CVSS 3.0) with the record still in received status; CISA added it to the Known Exploited Vulnerabilities catalogue on 16 September 2026 alongside the Cisco ISE flaw.

Attribute Detail
CVE CVE-2026-87886
CVSS 7.8 (High, CVSS 3.0)
Vendor / product Acronis / Backup plug-ins for cPanel & WHM, Plesk and DirectAdmin (Linux)
Reported 2026-09-16

The affected builds are the Acronis Backup plug-in for cPanel & WHM (Linux) before build 1.9.3.1021, the Backup extension for Plesk (Linux) before build 1.8.11.638 and the Backup plug-in for DirectAdmin (Linux). Insecure permissions on a local path mean an attacker who already has a foothold on the host can elevate to the privileges the backup agent runs with β€” and backup agents are a high-value target precisely because they hold credentials and access paths into everything they protect. The practical control is to confirm the agent's patched build number on each hosting node rather than relying on a panel-level update check, and to review who holds local accounts on those hosts.