boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-87886

Acronis Acronis Backup plugin for cPanel & WHM — Local privilege escalation due to insecure file permissions.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0023   12.9   YES
AFFECTED
  Product                                 Versions       Fixed
  Acronis Backup plugin for cPanel & WHM  unspecified –  —
  Acronis Backup extension for Plesk      unspecified –  —
  Acronis Backup plugin for DirectAdmin   unspecified –  —
TIMELINE
  Sep 9   Reserved by Acronis
  Sep 17  ADDED TO KEV — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Remediation due September 19, 2026.
  Sep 17  Published (CNA: Acronis)
  Sep 18  EXPLOIT PUBLISHED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Public exploit reference added.
  Sep 20  DUE DATE PASSED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). CISA remediation deadline was September 19, 2026; still in catalog.
CWE-276 · CNA: Acronis · CVSS v3.0 · 2 references · NVD status: Analyzed · KEV due September 19, 2026

Description

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
September 9, 2026ReservedReserved by Acronis
September 17, 2026KEV ADDEDADDED TO KEV — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Remediation due September 19, 2026.
September 17, 2026PublishedPublished (CNA: Acronis)
September 18, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Public exploit reference added.
September 20, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). CISA remediation deadline was September 19, 2026; still in catalog.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
AcronisAcronis Backup plugin for cPanel & WHM—unspecified—
AcronisAcronis Backup extension for Plesk—unspecified—
AcronisAcronis Backup plugin for DirectAdmin—unspecified—

Weaknesses

CWE-276

References (2)

Related

Authoritative record: CVE-2026-87886 at cve.org

Vendors: acronis

Weaknesses: CWE-276

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-87886 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.