Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.
The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions –
- Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 – Fixed in 1.9.3 HF3
- Acronis Backup extension for Plesk (Linux) before build 1.8.11.638
Successful exploitation of the flaw could allow an attacker with low privileges to escalate their permissions on a susceptible Linux version, potentially enabling them to perform unauthorized actions or run arbitrary code that could impact the confidentiality and integrity of the application.


Leave a Reply