Acronis Warns of Exploited Privilege Flaw in Backup Plugins

Acronis Warns of Exploited Privilege Flaw in Backup Plugins

Acronis says attackers are actively exploiting a high-severity privilege escalation flaw in its cPanel/WHM and Plesk backup plugins; users should update now.

Acronis has warned that a high-severity security vulnerability in its backup plugin for cPanel and Web Host Manager (WHM) is being actively exploited in limited, targeted attacks. The flaw is tracked as CVE-2026-87886 and carries a CVSS score of 7.8, which indicates high severity. cPanel is one of the most widely used web hosting control panels, giving website owners and hosting providers a browser-based interface for managing sites, email accounts, and files. WHM is the server administration side of that same software, used by hosting companies and resellers to manage multiple cPanel accounts on a server. A backup plugin is an add-on that automates the process of copying website files, databases, and other server data so they can be restored after an incident, and because it has deep access to server resources, a flaw in it can be dangerous.

According to Acronis, the vulnerability is a local privilege escalation caused by insecure file permissions. In practical terms, a local privilege escalation is a weakness that lets a user with limited access on a Linux server gain higher, more powerful permissions than they should have. When file permissions are set too loosely, a low-privilege user may be able to read, change, or replace files that belong to a more privileged account. If the flaw is exploited successfully, an attacker could run unauthorized commands or arbitrary code, which could affect the confidentiality and integrity of the hosting application.

The affected products are the Acronis Backup plugin for cPanel and WHM on Linux before build 1.9.3.1021, which is fixed in version 1.9.3 HF3, and the Acronis Backup extension for Plesk on Linux before build 1.8.11.638. Plesk is another popular control panel used by hosting providers and site owners to manage web servers. Acronis published a separate advisory for the 1.9.3 HF3 update and stated that the update contains fixes for one high-severity security vulnerability and should be installed immediately by all users. The company also confirmed that exploitation of this vulnerability has been detected in the wild in limited, targeted attacks.

The source report does not include details about how the vulnerability is being exploited, who is behind the attacks, or what their ultimate goals are. It is also not clear when the malicious activity was first detected or how long the flaw may have been exploited before the warning. The Hacker News, which reported the advisory, said it contacted Acronis for comment and would update the story if the company responds. Until more information is available, hosting providers and site owners should treat this as an actively exploited vulnerability and act quickly.

Backup plugins are a common part of hosting setups because they automate safety copies, but they also run with high privileges so they can reach every file and database on a server. An insecure file permission in such a plugin can allow a local user, for example someone with a limited hosting account on a shared server, to modify the plugin's own files and then use its high-level access to take control or interfere with other accounts. That is why a privilege escalation flaw in a backup tool is especially serious for shared hosting environments, where many customers rely on the same server staying isolated from one another.

For website owners and hosting businesses, the practical risk is concentrated on servers where the Acronis backup plugin or extension is installed. On a typical web hosting server, many customer accounts may exist with limited privileges, and a local privilege escalation flaw can allow one compromised or malicious account to break out of its limits and affect other sites or the whole server. That makes patching urgent even if you do not believe your own account has been targeted. If you run cPanel, WHM, or Plesk and use Acronis backup, install the fixed build now. If your website is hosted by a provider, ask the provider to confirm the patch has been applied.

Acronis customers are advised to apply the latest updates as soon as possible. Because the vulnerability is already being exploited, delaying the update leaves a known opening that attackers could use. Keeping control panel plugins up to date is one of the most effective ways to protect a hosting environment, because these tools often have deep access to server resources. For site owners who prefer not to manage server-side plugins and updates themselves, managed hosting services can take on that operational work; AEU Hosting, for example, offers managed WordPress hosting secured end to end.

How to Protect Yourself

  1. If you manage a server with the Acronis Backup plugin for cPanel, WHM, or Plesk, install the fixed version from Acronis right away.
  2. If your website is hosted by a provider, contact their support team and ask them to confirm the Acronis backup plugin is updated to the safe version.
  3. Make sure only trusted people have login access to your hosting control panel or server, because this flaw lets a limited user gain more power.
  4. Keep a separate, recent backup of your website and files in a different location so you can restore if anything goes wrong.
  5. Watch for any unusual activity in your hosting account, such as new admin users or file changes you did not make.

Vulnerabilities & Fixes

  • CVE-2026-87886 The vulnerability is a local privilege escalation due to insecure file permissions; Acronis fixed it in build 1.9.3 HF3 for the cPanel & WHM plugin and build 1.8.11.638 for the Plesk extension. View the fix & details →

Terms Explained

  • cPanel A popular control panel that lets website owners and hosting providers manage websites, email accounts, and server settings through a web browser.
  • WHM Web Host Manager, a server administration interface often used with cPanel to manage multiple hosting accounts.
  • Plesk A control panel similar to cPanel, used to manage websites and server services on Linux and Windows servers.
  • Privilege escalation A security weakness that lets a user with limited access gain higher, more powerful access on a computer or server.
  • CVE Common Vulnerabilities and Exposures, a public list that gives each known security flaw a unique identification number.
  • CVSS Common Vulnerability Scoring System, a standard way to rate the seriousness of a security flaw with a number from 0 to 10.
  • Build A specific version of software, often identified by a number, that contains a set of fixes and changes.
  • File permissions Rules that control which users can read, change, or run a file on a system.

Related AEU services