HIGH
CVE-2026-87886
CVSS
7.8
KEV
Description
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Weakness (CWE)
CWE-276
Incorrect Default Permissions
EPSS Score
0.28%
Probability of exploitation in next 30 days
20.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.