Acronis varoittaa cPanel- ja Plesk-varmuuskopioliitännäisten kriittisestä haavoittuvuudesta (CVE-2026-87886), jota hyödynnetään aktiivisesti Linux-palvelinten root-oikeuksien saamiseksi.
Cyber protection and data resilience provider Acronis has issued an urgent security bulletin confirming that a high-severity local privilege escalation vulnerability affecting its backup extensions for cPanel, WebHost Manager (WHM), and Plesk is being actively leveraged in targeted attacks. Tracked as CVE-2026-87886 with a CVSS v3.1 score of 7.8, the security defect allows an attacker holding low-level user access on a Linux hosting server to elevate privileges to root, effectively compromising all co-located tenant environments.
The flaw exists within the background synchronization daemons and helper scripts used by the Acronis backup plugins to interface web hosting management panels with external storage repositories. In multi-tenant environments typical of shared hosting providers, unprivileged customer accounts operate within isolated virtual directories. By abusing insecure temporary file creation and race conditions in how the Acronis extension processes local requests, an adversary with access to a single low-privileged account can replace target binaries with malicious symlinks, coercing root-level execution daemons into executing arbitrary shellcode.
Attaining root access on a web hosting server breaks the security perimeter between hosted tenants. Attackers can extract plain-text database credentials, dump customer databases, alter active website source code to inject payment-stealing skimming scripts, and subvert existing backup snapshots to neutralize disaster recovery procedures during extortion attempts.
Acronis stated that "exploitation of this vulnerability has been detected in the wild in limited targeted attacks." With thousands of managed service providers (MSPs) and web hosts relying on cPanel and Plesk integrations, immediate patching is vital to prevent broad lateral compromise across hosting infrastructures.
Recommended Actions for IT and Server Administrators
- Deploy Official Patches Immediately: Update Acronis Backup extensions for cPanel, WHM, and Plesk to the latest patched releases via the official package manager.
- Audit File Permissions and Temporary Directories: Inspect `/tmp`, `/var/tmp`, and panel installation paths for unauthorized symlinks and scripts spawned by web server users.
- Review Root Crontabs and Services: Verify systemd unit files and scheduled tasks to detect unauthorized persistence mechanisms planted prior to patch application.
- Rotate API Credentials and Database Secrets: If signs of compromise are identified, isolate the server instance, capture forensic memory images, and systematically regenerate all administrative credentials.
Suositellut toimenpiteet tietoturvasta vastaaville
- Valmistajan julkaisemien tietoturvapäivitysten välitön asentaminen.
- Järjestelmälokien ja verkkoliikenteen tehostettu valvonta.