Acronis Backup is at the center of a warning for CVE-2026-87886, a serious local elevation of privilege vulnerability in Linux that has been identified in limited, targeted attacks. The development affects cPanel, WHM, and Plesk installations and requires immediate patching.
According to BleepingComputer, Acronis identified the activity after receiving a report from a potentially affected customer. The company has not yet released technical details or specific indicators of the breach, to give administrators time to implement available fixes.
See also: Red Heron: Chinese group exploits critical vulnerability in Gitea
The Acronis Backup vulnerability and its scope
CVE-2026-87886 has a CVSS score of 7.8 and allows a low-privileged user to escalate their access level to the affected Linux server. Successful exploitation could lead to access or modification of sensitive data, as well as disruption of system operation, without requiring action from another user.
The issue is found in the Acronis Backup plugin for cPanel and WHM, as well as the Acronis Backup extension for Plesk. In hosting environments where multiple websites and accounts coexist on the same Linux server, a vulnerability in the permissions of a backup plugin can affect more than one customer.

Acronis says the exploit has been observed “in limited, targeted attacks.” The wording doesn’t document a widespread campaign, but it’s enough to make the issue a priority for hosting providers and teams managing multiple dashboards.
Who is affected by CVE-2026-87886?
In cPanel and WHM, builds of the Acronis Backup plugin older than 1.9.3.1021. The fixed version is available as 1.9.3 HF3. In Plesk, the issue affects builds earlier than 1.8.11.638, with version 1.8.11 containing the fix.
Version numbers must be checked separately for each installation, as an organization may use cPanel and Plesk at the same time. Simply updating the operating system is not enough if the Acronis Backup plugin remains on a vulnerable build.

See also: LiteSpeed Enterprise: Critical vulnerability allows root access to shared servers
What should administrators do?
The key action is to immediately install the patched builds on all infrastructures using Acronis Backup. Administrators should log in to cPanel, WHM, and Plesk systems, check the version of each add-on, and confirm that the update completed without errors.
At the same time, you need to check the logs for unusual backup actions, configuration changes, or processes that were run with permissions different than expected. Acronis has not published specific indicators of compromise, so the search must be based on the normal profile of each server and each account.

If the update cannot be done immediately, the SecNews technical team recommends temporarily restricting access to the admin panels to trusted networks and disabling the add-on only after assessing the impact on recovery processes. Backups should remain available, but also protected from unauthorized access.
See also: ZcopyReaper: Critical vulnerability in Linux Kernel leads to root access
CVE-2026-87886 shows why backup management plugins should be treated as critical infrastructure components rather than utility tools. Until more information about the limited exploit is available, the safest option is to upgrade to patched versions and carefully monitor affected servers.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Particular care is needed in shared hosting environments. Elevating privileges from an account with limited access can turn a problem on a single website into a risk to other customers' data or to the server's own management functions.
After installing the update, security managers should re-run the permissions check, confirm that no old versions remain on backup nodes, and keep relevant logs available. The SecNews technical team also recommends changing any credentials used in suspicious sessions.
The absence of published indicators should not be taken as an indication that there is no risk. In a targeted attack, attackers may seek to remain discreet and avoid actions that immediately trigger alerts. For this reason, auditing should cover both dashboard applications and the operating system.
Hosting providers can leverage the opportunity for total control over segmentation, management accounts, and backup isolation. Maintaining separate, protected copies reduces the likelihood that a compromised account will lead to the loss or corruption of the only available copy.
