Security4 publishers2 min readPublished
Acronis bases its CVE-2026-87886 exploitation warning on one customer report
The 7.8-rated privilege escalation in Acronis' cPanel and WHM backup plugin needs a local account on the server to work. The hosting providers and MSPs that run those servers are the only party who can install the fix.
The Watch · Security desk

What happened
- The flaw comes from insecure file permissions and lets an authenticated user escalate privileges locally on a Linux server with no user interaction, at a CVSS score of 7.8.
- Affected are all Linux builds of the cPanel and WHM plugin earlier than 1.9.3.1021 and Plesk extension builds earlier than 1.8.11.638.
- A brief advisory appeared over the preceding weekend, and the version carrying the CVE identifier and the 7.8 score followed on Tuesday, September 15, 2026.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure For a hosted site owner, whether the box running their site gets fixed depends entirely on their provider's change window.
- capability Elevated privileges on that host sit alongside the software whose job is reading and restoring every hosted account's files, databases and mailboxes.
- constraint Indicators of compromise remain unpublished, so a provider cannot determine whether it was already hit. Installing the build is the only action available.
Local privilege escalation is a second step. CVE-2026-87886 does nothing until an attacker already holds an authenticated account on the Linux server [3]. Those servers exist to run other people's websites, files, databases, mailboxes and hosting accounts through cPanel, WHM or Plesk [15][16]. The CVSS string also describes low attack complexity, meaning no conditions outside the attacker's control have to line up [5].
"Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments," Acronis said in its advisory [1]. In a statement to BleepingComputer, the company said that assessment is based on a single report from a "potentially affected" customer [9]. Acronis did not disclose when the activity occurred or what the attackers achieved past the escalation itself [10]. It is holding back technical detail so that administrators can patch first, BleepingComputer reported [11].
The fixed builds went out the week before the CVE-numbered advisory, according to Help Net Security [13]. On cPanel and WHM, anything earlier than build 1.9.3.1021 is affected and the fix is labelled 1.9.3 HF3; on Plesk the line is build 1.8.11.638, labelled 1.8.11 [7][8]. The label and the build string are different numbers, so confirming that a host is patched means reading the build [20]. Acronis says it has seen no exploitation of the Plesk extension [6].
Acronis is widely used by web hosting providers and managed service providers because they can offer its backup and security to their own clients under their own branding [14]. Those providers own this patch. The plugin runs on their server and is administered through WHM or Plesk, so the version to check and the hotfix to apply both sit with the provider, out of reach of the customer whose site sits on that box [19].
The impact described in the advisory is bounded to the host: a low-privileged attacker raising their permission level, then accessing or modifying sensitive data and disrupting the system, without user interaction [21]. On a hosting server, the software that does the reading is the backup plugin itself [16].
What to watch
- Whether Acronis publishes technical detail or indicators of compromise once it judges the patch window closed. That would give providers something to hunt on.
- A second in-the-wild report, or any exploitation against the Plesk extension. Acronis says it has seen no Plesk exploitation.
- Any disclosure of what the attackers did after escalating privileges on the affected cPanel and WHM host.