CVE-2026-87886: Insecure File Permissions in Acronis Backup Plugins
CERT-In issued advisory CIVN-2026-0466 about privilege escalation in Acronis Backup plugin for cPanel & WHM and Plesk extension due to insecure file permissions. Builds before 1.9.3.1021 and 1.8.11.638 are vulnerable; fix in update per Acronis SEC-10986.
- Vulnerability allows local user to escalate privileges and execute code on hosting
- Affected builds: cPanel & WHM before 1.9.3.1021 and Plesk before 1.8.11.638
- CERT-In assigned high severity on September 18, 2026
- No public exploits, but initial host access required
Read next
Security