Acronis has revealed that a serious security vulnerability in its Backup plugin for cPanel and Web Host Manager (WHM) on Linux systems is actively exploited. Identified as CVE-2026-87886 and carrying a CVSS score of 7.8, this privilege escalation flaw stems from insecure file permissions and puts systems using the affected plugin at real risk.
What’s Impacted
The issue affects versions of the Acronis Backup plugin for cPanel & WHM on Linux earlier than build 1.9.3.1021; it is addressed in the newer maintenance release, build 1.9.3 HF3. Also vulnerable is the Acronis Backup extension for Plesk on Linux up through build 1.8.11.638. Systems still running older versions are exposed to potential attackers seeking to elevate privileges from low-level accounts.
What Attackers Can Do & What’s Known So Far
If exploited, a low-privileged user could gain higher access rights, possibly allowing them to perform unauthorized operations or execute arbitrary code. That includes threats to both the confidentiality and integrity of the host. So far, successful exploitation of this vulnerability has been observed in the wild—but only in targeted scenarios. The vendor’s patches are designed to neutralize the issue completely.
There are no public details yet about who is behind these attacks, what their goals are, or how long the vulnerability has been actively exploited. Official disclosures do not name the affected organizations—or whether the exploit pre-dated awareness by days, weeks, or longer.
All users running vulnerable builds are urged to update immediately. For cPanel & WHM, move to build 1.9.3 HF3 or later; for Plesk, upgrade past build 1.8.11.638. Applying these updates is essential to block ongoing risks.
The timing of detection, and which systems have been breached, remain largely private—partly due to the specificity of the attacks observed. It’s a reminder of how even maintenance plugins can become critical weak points when permissions are handled poorly.
Going forward, administrators should verify file permissions not only in core systems but in all add-ons, verify update history, and monitor for unusual privilege escalations. Risk mitigation includes using file integrity monitoring tools and adopting a least-privilege access model wherever possible.
Why this matters: plugins like those from Acronis are widely used in shared hosting environments where a single compromised account can quickly impact many users. When escalations are possible at all, attackers gain the kinds of footholds that lead to full system compromise. Going forward, the focus must shift beyond patching to proactive oversight of configurations, permissions, and operational hygiene. Administrators should watch for additional disclosures, threat indicators, and ensure their systems are comprehensively updated.