Acronis disclosed a high-severity local privilege escalation vulnerability in its Backup plugin for cPanel and Web Host Manager that attackers have already exploited in the wild.

CVE-2026-87886 carries a CVSS score of 7.8, indicating high severity. The flaw stems from insecure file permissions that allow authenticated local users to escalate their privileges on affected systems. For hosting providers and web administrators managing multiple customer accounts through cPanel and WHM, this represents a direct path for an attacker with basic system access to gain root or administrator-level control.

The vulnerability affects Acronis Backup plugin installations on Linux systems running cPanel and WHM. These platforms serve as control panels for shared and dedicated hosting environments, managing thousands of customer websites and email accounts. When properly configured, cPanel and WHM enforce separation between customer accounts. A privilege escalation flaw ruptures that isolation, letting a compromised or malicious user account break containment and access other customers' data, configurations, and billing information.

Acronis confirmed that threat actors actively exploited this vulnerability before the patch became available. The company has not disclosed the scope of attacks or identified specific threat groups involved. However, the targeting pattern suggests attackers leveraged known Acronis installations to compromise hosting infrastructure. Given cPanel's widespread deployment across the hosting industry, the attack surface extends to thousands of providers and millions of hosted customer accounts globally.

Hosting providers prioritize patching this type of vulnerability because exploitation directly compromises customer data separation. A single breach at the infrastructure layer affects every account on that server. Customer websites, databases, email, SSL certificates, and backups all become accessible to the attacker. Data theft, malware injection, ransomware deployment, and service disruption all follow naturally from privilege escalation on cPanel systems.

The insecure file permissions weakness suggests that Acronis failed to restrict access to sensitive plugin files or directories during installation or operation. This represents a configuration and design failure rather than a complex exploitation technique. Red teams and attackers routinely scan for permission misconfigurations because they rarely require sophisticated exploitation code. Standard Linux tools like "find" and "chmod" often suffice.

Acronis released patched versions addressing this flaw. Administrators managing cPanel and WHM installations must apply the update immediately. The vulnerability requires local system access, eliminating the risk of remote unauthenticated attacks. However, many hosting environments contain thousands of customer accounts with varying levels of system access. Shared hosting environments pose the highest risk, as multiple unrelated customers share the same server.

Administrators should review recent access logs and user activity on affected systems to detect potential exploitation. Changes to file permissions, new user accounts, privilege escalation attempts, and unusual administrative activity all warrant investigation. Backup integrity audits also help identify whether attackers copied sensitive data before patching.

This vulnerability joins a broader pattern of attacks targeting hosting control panel infrastructure. Compromising cPanel, Plesk, and similar platforms provides attackers concentrated access to customer data. The hosting industry remains a high-value target for financially motivated threat actors and corporate espionage operations alike.