Summary
- CVE-2026-87886 is a high-severity local privilege-escalation flaw caused by insecure file permissions.
- Acronis says exploitation has been detected in limited, targeted attacks against its cPanel and WHM plugin.
- The Plesk extension is also vulnerable, although exploitation has not been reported against it.
Acronis has issued urgent updates for a high-severity vulnerability affecting backup integrations for cPanel, WHM, and Plesk after detecting limited exploitation against cPanel deployments.
CVE-2026-87886 is caused by insecure file permissions and can allow local privilege escalation on affected Linux systems. It carries a CVSS score of 7.8.
The vulnerability affects Acronis Backup plugin for cPanel & WHM builds before 1.9.3.1021 and Acronis Backup extension for Plesk builds before 1.8.11.638. The cPanel and WHM plugin is fixed in 1.9.3 HF3.
Acronis said exploitation has been detected “in limited, targeted attacks” against cPanel and WHM deployments. The company has not reported exploitation against the Plesk extension.
Public technical detail remains limited, and there is no basis to identify a threat actor or establish the attacker’s wider objectives. Reporting on the case indicates Acronis’s exploitation assessment is based on a single potentially affected customer report.
The flaw requires some level of local access rather than providing unauthenticated remote entry from the internet. That reduces its value as an initial-access mechanism but does not remove its importance.
Privilege escalation can turn a constrained account into much broader control of an underlying host, particularly when vulnerable software is already operating with elevated permissions.
Backup technology is sensitive in that respect. Products responsible for copying, restoring, and managing data often require access across filesystems and workloads that ordinary applications do not possess.
In hosting environments, one platform may also support multiple customers or websites. A weakness in a shared administrative or backup layer can therefore create consequences beyond a single application.
Ransomware and other intrusion groups have increasingly targeted recovery infrastructure because it can provide valuable data, privileged access, or a way to interfere with restoration. That makes backup tooling part of the attack surface rather than a system that can automatically be assumed to sit outside it.
The available evidence does not show that CVE-2026-87886 was used by ransomware operators, nor that it provided the initial entry point in the attacks Acronis observed. Its confirmed role is narrower: an attacker with sufficient local access may be able to elevate privileges through insecure file permissions.
The incident also carries a third-party dimension for hosting companies and managed service providers. Backup extensions may be deployed centrally across large numbers of systems, and customers may have little visibility into the privileged components operating underneath their individual sites or services.
Acronis has released corrected builds and urged affected users to update. The exploitation evidence makes that maintenance work more than a theoretical hardening exercise, particularly for cPanel and WHM environments where the company says attacks have already occurred.




