> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2026-87886 Acronis Backup: Acronis Backup Incorrect Default Permissions Vulnerability
- URL: https://f4n6.co.uk/security-feed/cve-2026-87886-acronis-backup-acronis-backup-incorrect-default-permissions-vulnerability/
- Published: 2026-09-16T20:46:13.000Z
- Updated: 2026-09-16T20:46:13.000Z
- Author: Jeff Davies
- Tags: #security-feed, CVE-2026-87886

## 1\. Executive summary

CVE-2026-87886 is a high-severity incorrect default permissions flaw in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk that allows local privilege escalation on Linux hosts. Acronis has confirmed exploitation in the wild in limited, targeted attacks against cPanel & WHM deployments; no exploitation has been observed against Plesk deployments. EMEA financial services firms are exposed only where they — or their hosting providers — run the affected plugin, but those that do should treat this as urgent, because the vulnerable component sits on backup infrastructure and privilege escalation there can compromise both data and recovery capability. **Confidence caveat:** no verified reference data resolved for this CVE, so the CVSS score (7.8) and the exploitation status below are source-reported and single-sourced; the CISA-ADP-style due date of 2026-09-19 carried in the NVD entry is not corroborated by our reference data and should not be treated as a confirmed KEV remediation deadline.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. This is a vendor vulnerability disclosure with confirmed in-the-wild exploitation, but the supplied material identifies no affected EMEA financial entity, no incident on client infrastructure, and no third-party arrangement specific enough to trigger a named obligation. If a client confirms exploitation on its own systems, incident-management and reporting obligations would be engaged by that confirmed incident; that determination rests on facts not present in this item.

## 3\. Technical analysis & attack chain

**Affected products (confirmed):** Acronis Backup plugin for cPanel & WHM (Linux) and Acronis Backup extension for Plesk. The Hacker News states the flaw "affects the following versions" but the supplied excerpt is truncated at that point — **no specific affected or fixed version numbers are available in the source material**, and none are asserted here.

### Confirmed attack chain

1. **Precondition — local access.** The flaw is a *local* privilege escalation. An attacker must already hold a foothold on a Linux host running the affected Acronis Backup plugin. The sources do **not** describe how that initial local access is obtained; no initial-access vector is confirmed.
2. **Exploitation of incorrect default permissions.** The attacker leverages incorrect default file permissions on the plugin to escalate privileges on the host. The NVD entry classifies the flaw as "incorrect default permissions"; SecurityWeek and The Hacker News describe it as "insecure file permissions." These describe the same class of flaw (CWE-276) — no substantive discrepancy, only a difference in phrasing.
3. **Observed in the wild.** Acronis states: "Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments." There are currently no signs of active exploitation against Plesk deployments.

**What the sources do not provide.** The supplied material contains no detail on: the initial-access vector, the specific file or directory whose permissions are incorrect, the privilege level gained (e.g. root vs. plugin service account), any payload or post-exploitation tooling, persistence mechanism, command-and-control, lateral movement, data access or exfiltration, or observed impact beyond the fact of exploitation. Do not assume any of these; they are simply not in scope of the reporting available to us.

**Confidence.** The exploitation claim is attributable to Acronis's own advisory (published 2026-09-15) and is repeated by Help Net Security and The Hacker News — i.e. one primary vendor source, re-reported. The CVSS score of 7.8 appears only in The Hacker News and is single-sourced; SecurityWeek describes the flaw only as "high-severity." Treat the score as indicative, not verified. No threat actor is named in any source, so **no attribution is made and none should be inferred**.

## 4\. Mitigation & containment

### P1 — within 24 hours

- **Inventory exposure.** Identify every Linux host running cPanel & WHM or Plesk with the Acronis Backup plugin/extension installed. Include hosts operated by third-party hosting providers — ask those providers directly and in writing whether the plugin is deployed and whether it has been patched.
- **Apply the vendor fix.** Acronis published a security advisory on 2026-09-15; apply its mitigation/patch in accordance with vendor instructions. The supplied material does not contain a fixed version number — obtain it from the Acronis advisory before scheduling the change.
- **Hunt for local privilege escalation on those hosts.** Review for unexpected root-level processes, changes to ownership or permissions on the plugin's installation files, and newly created privileged accounts. This is generic hunting guidance, not a signature derived from a published IOC — no atomic indicators are available (see §5).
- **If compromise is suspected:** isolate the host, and treat backup data, backup credentials and any secrets stored on that host as potentially exposed. The plugin sits on backup infrastructure, so assume recovery capability is in scope of the incident.

### P2 — within 72 hours

- Restrict interactive/local access to backup hosts and enforce least privilege for hosting accounts that can reach the plugin — the flaw requires local access, so reducing who has it reduces exposure.
- Verify file permissions on the plugin's installation directories against vendor guidance and correct any deviation.
- Obtain written confirmation from hosting providers that the plugin has been patched on infrastructure they operate on your behalf.

### P3 — within 7 days

- Add the Acronis Backup plugin to the ICT third-party register and confirm the provider's contractual notification and remediation timelines.
- Re-test after patching to confirm the fix is in place.

**Note on the CISA due date.** The NVD entry carries a required action referencing CISA BOD 26-04 and a due date of 2026-09-19\. That is a US federal directive and is not directly binding on EMEA firms; we cite it only as a signal of urgency. Our verified reference data did not resolve a CISA KEV record for this CVE, so do not treat 2026-09-19 as a confirmed KEV deadline.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

The sources confirm in-the-wild exploitation but publish no hashes, filenames, paths, registry keys, domains, IP addresses, or command lines. No behavioural indicators specific enough to observe are described either — the only stated observable is the vendor's own detection of exploitation against cPanel & WHM deployments. Any IOC set circulating for this CVE should be treated as unverified until it can be tied to a primary source.

## 6\. Detection

Insufficient indicators to author detection rules.

The supplied material contains no threat artefacts — no distinctive strings, command-line flags, mutex names, scheduled-task or service names, file paths, registry keys, or hard-coded values. The only strings available are the CVE identifier and product names, which are reporting metadata rather than artefacts of the threat, and would produce rules that match coverage *about* the vulnerability rather than exploitation of it.

## 7\. Sources

- NVD — CVE-2026-87886 — https://nvd.nist.gov/vuln/detail/CVE-2026-87886 — published 2026-09-15
- SecurityWeek — "Acronis Patches Exploited Vulnerability in cPanel Backup Plugin" — https://www.securityweek.com/acronis-patches-exploited-vulnerability-in-cpanel-backup-plugin/
- Help Net Security — "Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)" — https://www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/ — 2026-09-16
- The Hacker News — "Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks" — https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

## 8\. Adverse Trace position

We assess CVE-2026-87886 as a genuine but narrowly scoped risk: a local privilege escalation in a backup plugin, requiring prior local access, with confirmed but "limited, targeted" exploitation against cPanel & WHM deployments only. The CVSS score of 7.8 and the exploitation status are source-reported and single-sourced — no verified reference data resolved for this CVE, and no CISA KEV record was confirmed — so we are not raising severity above what the sources support, and we explicitly do not attribute this to any named actor. Client impact is concentrated in EMEA financial entities that run the Acronis Backup plugin for cPanel & WHM on Linux, directly or through a hosting provider; for everyone else the exposure is nil. We will monitor the Acronis advisory for affected/fixed version numbers and for any published indicators, and will re-issue this advisory if either materialises. Clients who confirm exploitation on their own infrastructure should contact us immediately — that is the point at which incident-management and reporting obligations become live.

---

[Read the original source →](https://nvd.nist.gov/vuln/detail/CVE-2026-87886?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*