Backup software on shared hosting is a credentials-to-all-tenants concentration point. Acronis Backup for cPanel & WHM and Plesk has a default-permissions privilege escalation under limited targeted exploitation — and CISA’s federal clock hits September 19.
If you run multi-tenant Linux hosting with the Acronis plugin or extension, treat account-level footholds as potential whole-server problems until the agent is fixed.
What happened
Acronis advisory SEC-10986 covers CVE-2026-87886 (CVSS 7.8, CWE-276): incorrect default permissions in the Linux backup component let a local low-privileged user access resources or execute actions beyond their level.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Fixes shipped in Backup plugin for cPanel & WHM 1.9.3 HF3 and Backup extension for Plesk 1.8.11. Acronis reported limited, targeted exploitation in the wild. CISA added the CVE to KEV on September 16, 2026 with a BOD 26-04 due date of September 19, 2026 and forensic triage required.
Why it matters
Realistic kill chain: phished or weak hosting account (or webshell) → Acronis LPE to server-level privileges → access to backup data, system files, control-panel resources, and other customers’ workloads. One compromised site becomes a platform incident.
Backup agents that any customer account can influence sit inside the trust boundary. Default-permission bugs convert account footholds into multi-tenant compromise.
What to do first
- Inventory every cPanel/WHM and Plesk host running Acronis Backup; upgrade to 1.9.3 HF3 (cPanel) or 1.8.11 (Plesk) and verify the version string.
- Hunt for anomalous local privilege artifacts (unexpected sudoers, setuid binaries, new cron under backup service accounts).
- Review backup job definitions, restore/export history, and destination credentials for tampering since early September.
- Rotate root/reseller/panel credentials on hosts that were reachable while vulnerable; treat high-value tenants as potential exposure until proven clean.
- Segment backup storage and restrict which local accounts can touch the Acronis component.
Details
- CVE: CVE-2026-87886 (CVSS 7.8, CWE-276)
- Product: Acronis Backup plugin for cPanel & WHM; Backup extension for Plesk (Linux)
- Class: Incorrect default permissions → local privilege escalation
- Exploitation: Limited, targeted (vendor); KEV added 2026-09-16; due 2026-09-19
- Fixed: cPanel plugin 1.9.3 HF3; Plesk extension 1.8.11
- Advisory: Acronis SEC-10986
Hunt / verify
- Confirm plugin/extension build ≥ fixed versions on every host.
- Diff local users, sudoers, and backup service permissions against a known-good baseline.
- Correlate hosting panel login anomalies with subsequent backup-agent process activity.
Sources
- CISA: Adds Two KEVs (Sep 16, 2026) — includes CVE-2026-87886
- CISA Known Exploited Vulnerabilities Catalog — due 2026-09-19
- threat.wiki: CISA KEV Sep 16 — Cisco ISE + Acronis Backup
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.