vulnerability Acronis / Help Net Security / BleepingComputer

Acronis warnt vor aktiv ausgenutzter Sicherheitslücke in cPanel und Plesk – Angreifer kapern Webhosting-Server

Acronis warnt vor der aktiven Ausnutzung einer Privilegienerweiterungs-Schwachstelle (CVE-2026-87886, CVSS 7.8) in Backup-Erweiterungen für cPanel und Plesk zur Erlangung vollständiger Root-Rechte.

Acronis warnt vor aktiv ausgenutzter Sicherheitslücke in cPanel und Plesk – Angreifer kapern Webhosting-Server

Acronis warnt vor der aktiven Ausnutzung einer Privilegienerweiterungs-Schwachstelle (CVE-2026-87886, CVSS 7.8) in Backup-Erweiterungen für cPanel und Plesk zur Erlangung vollständiger Root-Rechte.

Cyber protection and data resilience provider Acronis has issued an urgent security bulletin confirming that a high-severity local privilege escalation vulnerability affecting its backup extensions for cPanel, WebHost Manager (WHM), and Plesk is being actively leveraged in targeted attacks. Tracked as CVE-2026-87886 with a CVSS v3.1 score of 7.8, the security defect allows an attacker holding low-level user access on a Linux hosting server to elevate privileges to root, effectively compromising all co-located tenant environments.

The flaw exists within the background synchronization daemons and helper scripts used by the Acronis backup plugins to interface web hosting management panels with external storage repositories. In multi-tenant environments typical of shared hosting providers, unprivileged customer accounts operate within isolated virtual directories. By abusing insecure temporary file creation and race conditions in how the Acronis extension processes local requests, an adversary with access to a single low-privileged account can replace target binaries with malicious symlinks, coercing root-level execution daemons into executing arbitrary shellcode.

Attaining root access on a web hosting server breaks the security perimeter between hosted tenants. Attackers can extract plain-text database credentials, dump customer databases, alter active website source code to inject payment-stealing skimming scripts, and subvert existing backup snapshots to neutralize disaster recovery procedures during extortion attempts.

Acronis stated that "exploitation of this vulnerability has been detected in the wild in limited targeted attacks." With thousands of managed service providers (MSPs) and web hosts relying on cPanel and Plesk integrations, immediate patching is vital to prevent broad lateral compromise across hosting infrastructures.

Recommended Actions for IT and Server Administrators

  • Deploy Official Patches Immediately: Update Acronis Backup extensions for cPanel, WHM, and Plesk to the latest patched releases via the official package manager.
  • Audit File Permissions and Temporary Directories: Inspect `/tmp`, `/var/tmp`, and panel installation paths for unauthorized symlinks and scripts spawned by web server users.
  • Review Root Crontabs and Services: Verify systemd unit files and scheduled tasks to detect unauthorized persistence mechanisms planted prior to patch application.
  • Rotate API Credentials and Database Secrets: If signs of compromise are identified, isolate the server instance, capture forensic memory images, and systematically regenerate all administrative credentials.

Empfohlene Maßnahmen für IT-Sicherheitsverantwortliche

  • Zeitnahe Installation der bereitgestellten Sicherheitsupdates.
  • Laufende Überwachung der Netzwerktelemetrie und Protokolldateien.

Quellen & Referenzen

← Alle Nachrichten Werkzeuge