A high-severity Linux local privilege escalation vulnerability has been discovered in Acronis backup plugins designed for cPanel, WebHost Manager (WHM), and Plesk, with evidence suggesting active exploitation in the wild. The flaw allows low-privileged attackers to elevate their permissions on vulnerable Linux servers, potentially granting access to sensitive information and the ability to disrupt system operations without requiring user interaction.

Web hosting providers and server administrators rely on cPanel & WHM and Plesk as graphical management interfaces for overseeing websites and servers. Acronis' backup add-ons extend these control panels by linking them to Acronis infrastructure, enabling administrators to perform backup and restore operations for websites, files, databases, mailboxes, and hosting accounts directly from the cPanel and Plesk dashboards.

Acronis released an initial advisory over the weekend before formally identifying the vulnerability as CVE-2026-87886 with a severity rating of 7.8. The company has withheld detailed technical information to allow administrators sufficient time to deploy available patches before broader disclosure occurs.

According to Acronis, the company has documented exploitation activity targeting its backup integrations. The advisory states: "Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments." However, Acronis clarified in a statement that this assessment stems from a single report originating from a "potentially affected" customer. The company has not disclosed specific indicators of compromise, the timing of the attacks, or what objectives attackers may have achieved beyond the privilege escalation described in the advisory.

Affected versions and patches

The vulnerability impacts the following product builds:

  • Acronis Backup plugin for cPanel & WHM versions prior to 1.9.3.1021, resolved in version 1.9.3 HF3
  • Acronis Backup extension for Plesk versions prior to 1.8.11.638, resolved in version 1.8.11

Acronis is urging all users of its backup solutions for cPanel & WHM and Plesk to apply the available updates without delay.