Acronis Warns of Actively Exploited Privilege Escalation Flaw in cPanel Backup Plugin
High-severity Linux local privilege escalation affects Acronis backup plugin for cPanel, WHM, and Plesk

Key Takeaways
- Acronis disclosed a high-severity local privilege escalation vulnerability in its cPanel/WHM/Plesk backup plugin.
- The flaw affects Linux systems and may allow local privilege escalation.
- Acronis reports the vulnerability is being actively exploited in the wild.
- Security updates have been released; users should update the plugin immediately.
- No detailed exploit instructions or specific CVE number were provided in the source summary.
Quick answers
- What happened?
- Acronis has disclosed a high-severity local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk. The flaw may be exploited by local attackers to elevate privileges on Linux systems. The vendor reports the vulnerability is being actively exploited in the wild and has released security updates urging immediate patching.
- Which products are affected?
- cPanel backup plugin, WebHost Manager (WHM), Plesk
- What should defenders do?
- Update the Acronis backup plugin to the latest version immediately. Apply all security patches released by Acronis for the affected plugins. Monitor for further advisories and restrict local access where possible.
Acronis has issued a security advisory regarding a high-severity local privilege escalation vulnerability affecting its backup plugin for cPanel, WebHost Manager (WHM), and Plesk. The flaw impacts Linux systems and, according to the advisory, may be exploited by local attackers to gain elevated privileges. Acronis states that the vulnerability is being actively exploited in the wild. The company has released security updates and strongly recommends that users update the backup plugin to the latest available version immediately to mitigate the risk. Details regarding the specific CVE identifier and technical exploit mechanics were not included in the initial reporting. The vulnerability poses a risk to web hosting environments relying on the affected Acronis plugin for system backups and management.
Security Details
Local privilege escalation vulnerability in Acronis backup plugin for cPanel, WHM, and Plesk on Linux systems. Reported as actively exploited in the wild. Specific CVE number and exploit details not disclosed in source summary.
Affected products
cPanel backup plugin, WebHost Manager (WHM), Plesk
Mitigation
Update the Acronis backup plugin to the latest version immediately. Apply all security patches released by Acronis for the affected plugins. Monitor for further advisories and restrict local access where possible.
Sources
BleepingComputer
Acronis warns of actively exploited flaw in its cPanel backup plugin
Sep 15, 2026 · 21:37
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



