Acronis Backup CVE-2026-87886: Hosting Plugin LPE — KEV Due September 19

By George Bailey   Published: 09/17/26   Updated: 09/17/26   2 min read

Backup software on shared hosting is a credentials-to-all-tenants concentration point. Acronis Backup for cPanel & WHM and Plesk has a default-permissions privilege escalation under limited targeted exploitation — and CISA’s federal clock hits September 19.

If you run multi-tenant Linux hosting with the Acronis plugin or extension, treat account-level footholds as potential whole-server problems until the agent is fixed.

What happened

Acronis advisory SEC-10986 covers CVE-2026-87886 (CVSS 7.8, CWE-276): incorrect default permissions in the Linux backup component let a local low-privileged user access resources or execute actions beyond their level.

Fixes shipped in Backup plugin for cPanel & WHM 1.9.3 HF3 and Backup extension for Plesk 1.8.11. Acronis reported limited, targeted exploitation in the wild. CISA added the CVE to KEV on September 16, 2026 with a BOD 26-04 due date of September 19, 2026 and forensic triage required.

Why it matters

Realistic kill chain: phished or weak hosting account (or webshell) → Acronis LPE to server-level privileges → access to backup data, system files, control-panel resources, and other customers’ workloads. One compromised site becomes a platform incident.

Backup agents that any customer account can influence sit inside the trust boundary. Default-permission bugs convert account footholds into multi-tenant compromise.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.