Acronis cPanel backup plugin flaw exploited to escalate privileges on hosting servers
Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.
- Check
- Update the Acronis Backup plugin for cPanel and WHM to the fixed version immediately, and update the Plesk extension too, then review shared servers for signs of privilege escalation and unauthorized access.
- Affected
- Web hosts and managed service providers running the Acronis Backup plugin for cPanel and WHM (CVE-2026-87886); an attacker with a foothold can escalate privileges to reach backups, system files, and tenants' data.
- Fix
- Patch the backup plugin and extension, tighten file permissions and account isolation on shared hosting, monitor for privilege escalation and backup access, and treat a compromised hosting account as a server-wide risk.