Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-87886

Quick assessment

Affected
Acronis Acronis Backup plugin for cPanel & WHM
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

由于文件权限配置不当,导致本地权限提升漏洞。以下产品受到影响:Acronis Backup for cPanel & WHM(Linux)构建版本低于 1.9.3.1021、Acronis Backup for Plesk(Linux)构建版本低于 1.8.11.638,以及 Acronis Backup for DirectAdmin(Linux)构建版本低于 1.2.3.238。

AI Predicted 7.8 Difficulty: Moderate KEV EPSS 0.25% · P17

Affected Version Matrix 3

VendorProduct Version RangeStatus
Acronis Acronis Backup extension for Plesk unspecified< 1.8.11.638 affected
Acronis Acronis Backup plugin for cPanel & WHM unspecified< 1.9.3.1021 affected
Acronis Acronis Backup plugin for DirectAdmin unspecified< 1.2.3.238 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-87886

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
缺省权限不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Acronis Acronis Backup plugin for cPanel & WHM unspecified ~ 1.9.3.1021 -
Acronis Acronis Backup extension for Plesk unspecified ~ 1.8.11.638 -
Acronis Acronis Backup plugin for DirectAdmin unspecified ~ 1.2.3.238 -

II. Public POCs for CVE-2026-87886

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-87886

登录查看更多情报信息。

Other References for CVE-2026-87886 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-87886

No comments yet


Leave a comment