Acronis Product Security Update Advisory (CVE-2026-87886)
Overview
An update has been released regarding a security vulnerability in Acronis products. The vulnerability is CVE-2026-87886, a local privilege escalation vulnerability.
Affected Products
- Acronis Backup plugin for DirectAdmin (Linux): Versions prior to 1.2.3.238.
- Acronis Backup extension for Plesk (Linux): Versions prior to 1.8.11.638.
- Acronis Backup plugin for cPanel & WHM (Linux): versions prior to 1.9.3.1021.
Resolved Vulnerability
- CVE-2026-87886.
- This is a local privilege escalation vulnerability affecting Acronis Backup plugins and extensions.
- According to the referenced guidance, the vulnerability is related to insecure file permissions.
Recommendations
Acronis has provided a Vulnerability Patch for this vulnerability through the latest update. If you are using the affected products, you must update to the latest version that addresses this vulnerability.
Vulnerability Patches
- Acronis Backup plugin for DirectAdmin (Linux): 1.2.3.
- Acronis Backup extension for Plesk (Linux): 1.8.11.
- Acronis Backup plugin for cPanel & WHM (Linux): 1.9.3 HF3.