Skip to content

security_identifier

CVE-2026-87886

Identifier for a Linux local privilege escalation flaw caused by insecure file permissions in Acronis' backup add-ons for cPanel, WHM and Plesk, rated 7.8 on CVSS.

Known aliases

  • Acronis backup plugin privilege escalation

Relationships

No evidence-backed relationships are recorded.

Current clusters

security4 publishers

Acronis bases its CVE-2026-87886 exploitation warning on one customer report

The 7.8-rated privilege escalation in Acronis' cPanel and WHM backup plugin needs a local account on the server to work. The hosting providers and MSPs that run those servers are the only party who can install the fix.

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 65%
Investor
Investor 10%

Reality

Evidence55
Adoption
Insufficient
Hype gap+32
Incentives70
Confidence62