Acronis Discloses Actively Exploited Local Privilege Escalation in cPanel/WHM/Plesk Backup Plugin
What Happened
Acronis has disclosed a high-severity local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk, according to a report from BleepingComputer. Acronis warns the flaw may be exploited in the wild. Specific technical details, a CVE identifier, affected version ranges, and root cause were not included in the summary available at this time.
Why It Matters for Defenders
This plugin runs on hosting control panel servers, which are high-value targets: a successful local privilege escalation on a shared hosting or web hosting management server can let an attacker who already has limited access (e.g., via a compromised customer account, web shell, or another initial-access vector) escalate to root or administrative control. Given cPanel, WHM, and Plesk are widely used by hosting providers and web hosts, organizations running Acronis backup integrations on these platforms — including managed hosting providers and any business relying on a hosting provider that uses this plugin — should treat this as relevant to their attack surface, even indirectly.
Who Is Affected
- Organizations directly running Acronis's backup plugin on cPanel, WHM, or Plesk servers
- Hosting providers and MSPs managing customer environments on these control panels
- Downstream customers of hosting providers that have not yet patched, since privilege escalation on a shared host can affect co-tenants
What Defenders Should Do Now
- Check with Acronis directly for the official advisory, affected version list, and patched release, since those details were not specified in the initial report
- Apply the vendor-supplied update as soon as it is confirmed available; treat this as urgent given the "actively exploited" characterization
- Until patched, review who has local/shell access to affected cPanel, WHM, and Plesk hosts and tighten it where possible, since local privilege escalation requires an existing foothold
- Hunt for anomalous process execution, unexpected privilege changes, or new root-level processes/cron jobs spawned from the backup plugin's service account or binary path
- Review authentication and command-execution logs on hosting control panel servers for unusual activity around the plugin's components
- If you are a hosting customer rather than the server operator, ask your provider whether they run the affected plugin and what their patch timeline is
Developing Story
This is a fast-developing advisory and full technical details (CVE ID, affected versions, exploitation indicators) were not available in the source report reviewed here. We will not speculate beyond what Acronis and BleepingComputer have published. For the latest information, see the original report: Acronis warns of actively exploited flaw in its cPanel backup plugin.