Volver a los avisos de seguridad

Acronis Backup for cPanel & Plesk CVE-2026-87886: Local Privilege Escalation

Acronis Backup plugin/extension for cPanel & WHM and Plesk is affected by CVE-2026-87886. Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux). Affected versions: cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238. Fixed in 1.9.3.1021 / 1.8.11.638 / 1.2.3.238. CVSS base score: 7.8.

High 7.8 CVSS Explotado activamente
cPanel DirectAdmin Plesk AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 7 CloudLinux 8 CloudLinux 9

Versiones afectadas

cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238

Versión parcheada

1.9.3.1021 / 1.8.11.638 / 1.2.3.238

CMD de actualización por defecto

# Update Acronis Backup from the marketplace in WHM or Plesk

Comandos de corrección

All supported operating systems

# WHM → Plugins → Marketplace → Installed → Acronis Backup → Update (≥ 1.9.3.1021)
# Plesk → Extensions → Updates → Acronis Backup → Update (≥ 1.8.11.638)

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense cPanel license itself is not affected — this is a vulnerability in Acronis Backup plugin/extension for cPanel & WHM and Plesk, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-87886

Preguntas frecuentes

What is CVE-2026-87886?
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux). Affected versions: cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238. Fixed in 1.9.3.1021 / 1.8.11.638 / 1.2.3.238.
Is CVE-2026-87886 being exploited in the wild?
Yes — CISA lists CVE-2026-87886 in the Known Exploited Vulnerabilities catalog. Treat patching as urgent and check for signs of compromise.
How do I fix CVE-2026-87886?
WHM → Plugins → Marketplace → Installed → Acronis Backup → Update (≥ 1.9.3.1021). Plesk → Extensions → Updates → Acronis Backup → Update (≥ 1.8.11.638).
Which versions are affected?
Affected: cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238. Update to 1.9.3.1021 / 1.8.11.638 / 1.2.3.238 or later.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema