CVE-2026-33092
Local Privilege Escalation in Acronis True Image macOS
Publication date: 2026-04-10
Last updated on: 2026-04-10
Assigner: Acronis International GmbH
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| acronis | true_image_oem | to 42571 (exc) |
| acronis | true_image | to 42902 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-15 | One or more system settings or configuration elements can be externally controlled by a user. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a local privilege escalation issue caused by improper handling of environment variables in certain versions of Acronis True Image software for macOS. It allows a local user to potentially gain higher privileges than intended by exploiting how environment variables are processed.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker with local access could escalate their privileges, gaining higher-level permissions on the affected system. This could lead to unauthorized access to sensitive data, modification of system settings, or installation of malicious software.