CVE-2026-87886
Analyzed
Analyzed - Analysis Complete
BaseFortify
Vulnerability report for CVE-2026-87886, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: Acronis International GmbH
Description
Description
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| acronis | acronis_backup | to 1.9.3 (exc) |
| acronis | acronis_backup | to 1.2.3 (exc) |
| acronis | acronis_backup | to 1.8.11 (exc) |
| acronis | acronis_backup | 1.9.3 |
| acronis | acronis_backup | 1.9.3 |
| acronis | acronis_backup | 1.9.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |