• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-87886: local privilege escalation in Acronis Backup

A local low-privileged user can gain elevated privileges on Acronis Backup server plugins and extensions due to insecure file permissions (CVE-2026-87886). The flaw affects Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021, the Backup extension for Plesk before build 1.8.11.638, and the Backup plugin for DirectAdmin before build 1.2.3.238. An attacker requires local access to the host where these Linux plugins/extensions are installed; no user interaction is required beyond that local presence.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.0
7.8HIGH
EPSS
0.00233
CWE
CWE-276
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a rapid remediation requirement, so prioritize updating or mitigating exposed hosts immediately. The decisive fact is CISA’s KEV listing and its short remediation deadline.

What is CVE-2026-87886?

A local low-privileged user can gain elevated privileges on Acronis Backup server plugins and extensions due to insecure file permissions (CVE-2026-87886). The flaw affects Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021, the Backup extension for Plesk before build 1.8.11.638, and the Backup plugin for DirectAdmin before build 1.2.3.238. An attacker requires local access to the host where these Linux plugins/extensions are installed; no user interaction is required beyond that local presence.

Vector CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Acronis Backup are affected?

BRANCHAFFECTEDFIXED
Acronis Backup plugin for cPanel & WHM 1.xunspecified – before 1.9.3.10211.9.3.1021
Acronis Backup extension for Plesk 1.xunspecified – before 1.8.11.6381.8.11.638
Acronis Backup plugin for DirectAdmin 1.xunspecified – before 1.2.3.2381.2.3.238

Is CVE-2026-87886 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-16, and US federal agencies were required to remediate it by 2026-09-19.

How to fix CVE-2026-87886

  1. Upgrade Acronis Backup plugin for cPanel & WHM to build 1.9.3.1021 or later.
  2. Upgrade Acronis Backup extension for Plesk to build 1.8.11.638 or later and the DirectAdmin plugin to build 1.2.3.238 or later.
  3. Restrict and monitor local access to hosts running these plugins; limit who can write to plugin files and directories.
  4. Follow Acronis vendor guidance and verify permissions and integrity after updating.

Frequently asked questions

Is CVE-2026-87886 being actively exploited?

CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on 2026-09-16, requiring remediation by 2026-09-19; there is no public exploit code reported as of 2026-09-29.

Which Acronis Backup versions are affected by CVE-2026-87886?

Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021, Backup extension for Plesk before build 1.8.11.638, and Backup plugin for DirectAdmin before build 1.2.3.238 are affected.

Is there a patch for CVE-2026-87886?

Yes; fixed builds are 1.9.3.1021 for the cPanel & WHM plugin, 1.8.11.638 for the Plesk extension, and 1.2.3.238 for the DirectAdmin plugin.

Does CVE-2026-87886 require authentication?

The vulnerability requires local low-privileged access to the host rather than remote authentication, since it stems from insecure file permissions on the installed plugins.

References