Catalog analysis: CISA added this entry on September 16, 2026. The entry reflects catalog information retrieved on September 17, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-87886 is a vulnerability characterized by incorrect default permissions (CWE-276). This flaw exists within specific Acronis Backup integrations and could allow an attacker to achieve privilege escalation on the affected system.
Exposure and applicability
This vulnerability specifically affects environments utilizing the following components:
* Acronis Backup plugin for cPanel & WHM
* Acronis Backup extension for Plesk
Infrastructure owners should identify all servers where these specific plugins or extensions are deployed. Because this vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, the risk is elevated for any internet-exposed assets running these configurations.
Remediation priorities
Our analysis suggests prioritizing remediation based on the level of asset exposure and the criticality of the data being backed up. The following actions are recommended:
- Immediate Mitigation Deployment: Apply the mitigations detailed in the vendor’s security advisory (SEC-10986). This is the primary corrective action to address the incorrect default permissions.
- Forensic Triage: Given that CISA has flagged this vulnerability for forensic triage, defenders should examine logs and system state for indicators of unauthorized privilege escalation prior to applying the fix.
- Exposure Assessment: Evaluate whether the affected cPanel or Plesk instances are directly accessible from the internet, as these assets represent a higher priority for immediate patching.
How to validate remediation
To ensure that exposure has been reduced, defenders must move beyond simple version checks. Validation should focus on the following:
* Permission Verification: Verify that the specific file or directory permissions identified in the vendor’s instructions have been corrected and are no longer set to the vulnerable defaults.
* Configuration Audit: Confirm that the mitigation has been applied consistently across all instances of the cPanel plugin and Plesk extension, rather than on a per-server basis.
Verification is complete only when the actual system permissions match the secure state defined by the vendor.
Limits and open questions
While the vulnerability is known to be exploitable, it remains unknown whether this flaw has been utilized in ransomware campaigns. Additionally, while CISA has set a remediation deadline of September 19, 2026, for covered federal agencies, other organizations must determine their own timelines based on internal risk tolerance.
Residual risk remains if the underlying system permissions are manually altered after mitigation or if third-party configurations override the vendor’s security settings.
Source and editorial note
CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability · Source date: September 16, 2026 · Retrieved September 17, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗