CVE-2026-41220
Local Privilege Escalation in Acronis DeviceLock DLP and Cyber Protect Cloud Agent
Publication date: 2026-04-29
Last updated on: 2026-04-29
Assigner: Acronis International GmbH
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| acronis | devicelock_dlp | to 9.0.93212 (exc) |
| acronis | cyber_protect_cloud_agent | to 42183 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a local privilege escalation issue caused by improper input validation in certain Acronis products. Specifically, it affects Acronis DeviceLock DLP (Windows) versions before build 9.0.93212 and Acronis Cyber Protect Cloud Agent (Windows) versions before build 42183.
How can this vulnerability impact me? :
The vulnerability can allow an attacker with limited privileges on the affected system to escalate their privileges to a higher level. This can lead to full control over the system, including the ability to read, modify, or delete sensitive data, install malicious software, or disrupt system operations.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability is a local privilege escalation due to improper input validation, which can lead to high impact on confidentiality, integrity, and availability as indicated by the CVSS score.
Such vulnerabilities can potentially affect compliance with standards like GDPR and HIPAA because unauthorized privilege escalation may lead to unauthorized access or modification of sensitive data, thereby violating data protection and privacy requirements.
However, specific impacts on compliance depend on the context of use and whether the affected products are used to process regulated data.
Can you explain this vulnerability to me?
This vulnerability is a local privilege escalation caused by improper input validation in certain Acronis products. Specifically, it affects Acronis DeviceLock DLP (Windows) versions before build 9.0.93212 and Acronis Cyber Protect Cloud Agent (Windows) versions before build 42183.
How can this vulnerability impact me? :
The vulnerability allows an attacker with limited privileges on the affected system to escalate their privileges locally. This can lead to full control over the system, including the ability to compromise confidentiality, integrity, and availability of data and system resources.