Acronis backup add-on carries a Linux privilege flaw, and someone is already using it
A high-severity bug in Acronis backup plugins for cPanel, WHM and Plesk is being exploited in what the vendor calls limited, targeted attacks. Patches are out.

Key points
- Acronis has patched a high-severity Linux privilege escalation bug, tracked as CVE-2026-87886, in its backup plugins for cPanel and Plesk.
- The flaw scores 7.8 and lets a low-privileged user on a Linux server gain higher permissions without any user interaction.
- Acronis says it has seen exploitation in limited, targeted attacks, based on a single report from a potentially affected customer.
- Fixed builds are Acronis Backup plugin for cPanel & WHM 1.9.3 HF3 (1.9.3.1021) and Acronis Backup extension for Plesk 1.8.11 (1.8.11.638).
- No indicators of compromise or attribution have been shared.
Acronis is telling web hosting providers to patch a backup add-on that an attacker is already abusing on Linux servers.
The bug sits in the Acronis Backup plugin for cPanel and WebHost Manager, and in the matching extension for Plesk. These are the control panels that hosting companies and server admins use to manage websites and databases through a point-and-click interface. The Acronis add-on connects those panels to the company's infrastructure so staff can back up and restore sites, files and whole hosting accounts.
Tracked as CVE-2026-87886 and scored 7.8 out of 10, it's a local privilege escalation flaw: a user who already holds a low-level account on the server can use it to promote themselves to a more powerful one, then read or alter sensitive data without touching another user. Acronis published a brief advisory last weekend and expanded it this week.
Is the flaw actually being exploited?
Yes, but cautiously stated. Acronis says it's detected exploitation "in limited, targeted attacks" against the cPanel and WHM plugin. In a statement to BleepingComputer, the company added that this rests on a single report from one "potentially affected" customer. That's thin sourcing, and worth reading with the same caution the vendor is applying.
Acronis hasn't published indicators of compromise, hasn't said when the activity started, and hasn't named a cluster or campaign. There's no attribution here, not even a hint. Treat this as capability confirmed, intent unclear.
Which versions need patching?
| Product | Vulnerable builds | Fixed in |
|---|---|---|
| Acronis Backup plugin for cPanel & WHM | earlier than 1.9.3.1021 | 1.9.3 HF3 |
| Acronis Backup extension for Plesk | earlier than 1.8.11.638 | 1.8.11 |
Acronis is holding back deeper technical detail to give administrators time to patch before a working exploit spreads. That's a reasonable call. The plugin sits on shared hosting infrastructure where a single server can hold hundreds of customer sites.
Should you worry if your site runs on shared hosting?
If you run a small business site through a hosting company, you don't patch this yourself. Your host does. Ask them, in plain terms, whether they use the Acronis Backup plugin for cPanel, WHM or Plesk and whether they've applied the fixed builds listed above. A good provider will answer quickly.
This is the fourth privilege-escalation story we've reported on cPanel-adjacent hosting infrastructure since August, following the cPanel EmailTrack root-write flaw we covered on 9 September. The pattern is worth tracking.
The interesting part of this story isn't the CVSS number. It's that a backup tool, the thing you install to recover from a bad day, has become the route an attacker climbs on a hosting server. Backup software runs with elevated privileges by design, which makes any local flaw in it a short walk to full control of the box. Expect more scrutiny of backup agents on Linux hosting stacks in the months ahead.



