Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Acronis Backup plugins for Linux hosting control panels ship files or directories with overly permissive default permissions, allowing a local attacker to escalate privileges on the affected host. The flaw affects the cPanel & WHM plugin before build 1.9.3.1021, the Plesk extension before build 1.8.11.638, and the DirectAdmin plugin before build 1.2.3.238. Exploitation has been confirmed in the wild in targeted attacks against cPanel & WHM deployments.
CWE-276 (Incorrect Default Permissions) describes a condition where software installation leaves files or directories accessible to users who should not be able to modify or execute them. In this case, the Acronis Backup plugins for Linux install components with permissions broad enough for a low-privileged local user to interact with them. Because backup agents typically run under elevated accounts to access system data, any writable script, binary, or configuration file in that trust chain becomes a privilege escalation vector. The attacker does not need to exploit a memory-safety flaw or bypass a network control; the file system itself is the attack surface.
An attacker with an existing low-privileged account on the Linux host where one of the affected plugins is installed can write to or otherwise manipulate the insecurely permissioned files left by the plugin. By replacing or modifying a file that a higher-privileged process reads or executes, the attacker causes that process to run attacker-controlled content, gaining elevated privileges consistent with high confidentiality, integrity, and availability impact on the local system. The vendor advisory confirms this path has been observed in limited, targeted attacks against cPanel & WHM deployments, making it an actively exploited local privilege escalation.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Acronis Backup runs inside your authorization boundary, CVE-2026-87886 affects your FedRAMP authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 19, 2026 has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. At this point, you either remediate it or formally document the mitigation and the delay.
Knox does not patch Acronis Backup on your behalf. Under the FedRAMP shared-responsibility model, remediating that vulnerability is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-87886 surfaces, exposure appears during continuous monitoring rather than only when an assessor flags it at a scheduled review, giving you time to act before the finding becomes a formal problem.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-87886 remains unremediated, it sits as an open Plan of Action and Milestones (POA&M) item on your authorization record. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding now and formally documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








