Back to Security Advisories

Acronis Backup for cPanel & Plesk CVE-2026-87886: Local Privilege Escalation

Acronis Backup plugin/extension for cPanel & WHM and Plesk is affected by CVE-2026-87886. Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux). Affected versions: cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238. Fixed in 1.9.3.1021 / 1.8.11.638 / 1.2.3.238. CVSS base score: 7.8.

High 7.8 CVSS Actively exploited
cPanel DirectAdmin Plesk AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 7 CloudLinux 8 CloudLinux 9

Affected Versions

cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238

Patched Version

1.9.3.1021 / 1.8.11.638 / 1.2.3.238

Default Update CMD

# Update Acronis Backup from the marketplace in WHM or Plesk

Fix Commands

All supported operating systems

# WHM → Plugins → Marketplace → Installed → Acronis Backup → Update (≥ 1.9.3.1021)
# Plesk → Extensions → Updates → Acronis Backup → Update (≥ 1.8.11.638)

What this means under a SharedLicense license

Your SharedLicense cPanel license itself is not affected — this is a vulnerability in Acronis Backup plugin/extension for cPanel & WHM and Plesk, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-87886

Frequently Asked Questions

What is CVE-2026-87886?
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux). Affected versions: cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238. Fixed in 1.9.3.1021 / 1.8.11.638 / 1.2.3.238.
Is CVE-2026-87886 being exploited in the wild?
Yes — CISA lists CVE-2026-87886 in the Known Exploited Vulnerabilities catalog. Treat patching as urgent and check for signs of compromise.
How do I fix CVE-2026-87886?
WHM → Plugins → Marketplace → Installed → Acronis Backup → Update (≥ 1.9.3.1021). Plesk → Extensions → Updates → Acronis Backup → Update (≥ 1.8.11.638).
Which versions are affected?
Affected: cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238. Update to 1.9.3.1021 / 1.8.11.638 / 1.2.3.238 or later.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System