A newly highlighted security issue affecting widely used website management tools requires attention from small businesses and website administrators. The vulnerability, designated as CVE-2026-87886, involves an incorrect default permissions flaw within the Acronis Backup plugin for cPanel & WHM and the corresponding extension for Plesk.

With a high CVSS score of 7.8, this issue carries significant weight because it could potentially allow for privilege escalation on affected systems. Furthermore, this vulnerability is officially tracked on CISA's Known Exploited Vulnerabilities list, meaning active exploitation has been observed in the wild. You can review the technical specifics directly on our CVE-2026-87886 tracker page.

Who Should Care About This Vulnerability?

Small-business owners, web administrators, and IT support teams who manage their own hosting environments should pay close attention. If your web server relies on cPanel, WHM, or Plesk and utilizes the Acronis Backup plugin or extension, your hosting infrastructure could be exposed.

Privilege escalation vulnerabilities are particularly concerning because they may allow an unauthorized user to gain elevated access rights, potentially compromising the entire server environment where multiple business websites reside.

What You Should Do Now

Protecting your hosting environment from known threats requires prompt action. If you use Acronis Backup within your cPanel, WHM, or Plesk setup, consider taking the following steps:

  • Audit your hosting extensions: Check all installed plugins, extensions, and backup tools within your control panels to identify if the affected Acronis Backup product is present.
  • Consult official vendor advisories: Visit Acronis for official guidance, updates, and recommended remediation steps.
  • Apply updates promptly: Ensure that all server extensions and control panel integrations are updated to the vendor's latest secure versions.
  • Review user permissions: Verify that user roles and access privileges across your cPanel and Plesk environments adhere to the principle of least privilege.

Maintaining a secure web infrastructure involves continuous monitoring and staying informed about active threats affecting your specific software stack.

Ready to check your website security posture? Run a free scan today at Korisec.