Knox CVE Database
/
CVE-2026-87886
High
7.8

CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Added to the CISA KEV catalog:
September 16, 2026

Overview

Acronis Backup plugins for Linux hosting control panels ship files or directories with overly permissive default permissions, allowing a local attacker to escalate privileges on the affected host. The flaw affects the cPanel & WHM plugin before build 1.9.3.1021, the Plesk extension before build 1.8.11.638, and the DirectAdmin plugin before build 1.2.3.238. Exploitation has been confirmed in the wild in targeted attacks against cPanel & WHM deployments.

Vulnerability details

Affected vendor
Acronis
Affected product
Backup
Weakness type (CWE)
CWE-276

CWE-276 (Incorrect Default Permissions) describes a condition where software installation leaves files or directories accessible to users who should not be able to modify or execute them. In this case, the Acronis Backup plugins for Linux install components with permissions broad enough for a low-privileged local user to interact with them. Because backup agents typically run under elevated accounts to access system data, any writable script, binary, or configuration file in that trust chain becomes a privilege escalation vector. The attacker does not need to exploit a memory-safety flaw or bypass a network control; the file system itself is the attack surface.


An attacker with an existing low-privileged account on the Linux host where one of the affected plugins is installed can write to or otherwise manipulate the insecurely permissioned files left by the plugin. By replacing or modifying a file that a higher-privileged process reads or executes, the attacker causes that process to run attacker-controlled content, gaining elevated privileges consistent with high confidentiality, integrity, and availability impact on the local system. The vendor advisory confirms this path has been observed in limited, targeted attacks against cPanel & WHM deployments, making it an actively exploited local privilege escalation.

Severity and impact

7.8
High
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit Linux file-permission checks on Acronis Backup plugin installation directories: unexpected world-writable or group-writable files owned by a privileged account are a direct indicator of the vulnerable condition.
  • Monitor for unexpected privilege changes on the host, such as a low-privileged user spawning processes owned by root or the Acronis service account, which would indicate successful exploitation of the permission flaw.
  • Review authentication and sudo logs for low-privileged accounts on hosts running the affected plugins; lateral or privilege-escalation activity from those accounts with no corresponding administrative session is a post-exploitation signal.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 19, 2026

Additional hardening

  • Upgrade the affected plugins: cPanel & WHM plugin to build 1.9.3.1021 or later, Plesk extension to build 1.8.11.638 or later, and DirectAdmin plugin to build 1.2.3.238 or later. See the vendor advisory in References for package details.
  • Restrict local account access on Linux hosts running Acronis Backup plugins to only those users who require it; remove or disable shell access for service and application accounts that do not need interactive login.
  • Apply the principle of least privilege to the plugin installation directories: audit permissions with tools such as find and chmod, and ensure no plugin-owned files or directories are writable by unprivileged users pending the patch.
  • Where patching cannot be applied immediately, consider isolating affected hosts from shared multi-tenant environments (such as shared hosting nodes) to reduce the pool of local accounts that could reach the vulnerable files.

Key dates

Published (NVD)
September 17, 2026
Added to CISA KEV
September 16, 2026
Remediation deadline
September 19, 2026
Last updated
September 18, 2026

References

Frequently asked questions

Does CVE-2026-87886 affect my FedRAMP authorization?

If Acronis Backup runs inside your authorization boundary, CVE-2026-87886 affects your FedRAMP authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 19, 2026 has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. At this point, you either remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-87886?

Knox does not patch Acronis Backup on your behalf. Under the FedRAMP shared-responsibility model, remediating that vulnerability is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-87886 surfaces, exposure appears during continuous monitoring rather than only when an assessor flags it at a scheduled review, giving you time to act before the finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-87886's remediation deadline of September 19, 2026 has passed. What happens now?

If CVE-2026-87886 remains unremediated, it sits as an open Plan of Action and Milestones (POA&M) item on your authorization record. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding now and formally documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.