Acronis Product Security Update Advisory (CVE-2026-87886)

Acronis Product Security Update Advisory (CVE-2026-87886)

Overview

An update has been released regarding a security vulnerability in Acronis products. The vulnerability is CVE-2026-87886, a local privilege escalation vulnerability.

Affected Products

  • Acronis Backup plugin for DirectAdmin (Linux): Versions prior to 1.2.3.238.
  • Acronis Backup extension for Plesk (Linux): Versions prior to 1.8.11.638.
  • Acronis Backup plugin for cPanel & WHM (Linux): versions prior to 1.9.3.1021.

Resolved Vulnerability

  • CVE-2026-87886.
  • This is a local privilege escalation vulnerability affecting Acronis Backup plugins and extensions.
  • According to the referenced guidance, the vulnerability is related to insecure file permissions.

Recommendations

Acronis has provided a Vulnerability Patch for this vulnerability through the latest update. If you are using the affected products, you must update to the latest version that addresses this vulnerability.

Vulnerability Patches

  • Acronis Backup plugin for DirectAdmin (Linux): 1.2.3.
  • Acronis Backup extension for Plesk (Linux): 1.8.11.
  • Acronis Backup plugin for cPanel & WHM (Linux): 1.9.3 HF3.