SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-87886

HIGH · CVSS 7.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Local privilege escalation vulnerabilities exist in the Acronis Backup plugins for cPanel, Plesk, and DirectAdmin on Linux systems due to insecure file permissions. Exploitation of this flaw could allow an unprivileged user to gain elevated access, potentially compromising the entire system. Administrators using affected versions should prioritize patching to mitigate the risk of unauthorized access.

CVE
CVE-2026-87886
Severity
HIGH
CVSS
7.8
EPSS
N/A
Linux

Original NVD Description

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Related CVEs

Other vulnerabilities affecting the same vendor(s)