Acronis warns of actively exploited flaw in cPanel backup plugin
Acronis has disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WHM, and Plesk that is actively being exploited.

Data protection and cybersecurity firm Acronis has issued a warning regarding a high-severity security flaw found in its backup plugin designed for widely used web hosting control panels, including cPanel, WebHost Manager (WHM), and Plesk. The vulnerability involves a local privilege escalation issue on Linux systems and is reportedly being exploited in the wild.
According to the disclosure, the security gap carries a high severity rating, allowing attackers who may already have a foothold in a system to escalate their privileges and perform unauthorized actions. Because backup plugins often require elevated permissions to function, flaws in such components can pose significant risks to the underlying host.
Cybersecurity researchers and incident responders are closely monitoring the situation as threat actors look for ways to leverage unpatched installations. Acronis has urged users to apply necessary updates and security measures immediately to mitigate potential threats.
For system administrators, web hosting providers, and IT professionals globally, this alert highlights the critical importance of supply chain and third-party plugin security. Since control panels like cPanel and Plesk form the backbone of many web hosting environments, neglecting plugin updates can lead to severe server compromises.
Experts recommend that all administrators managing servers with Acronis backup plugins verify their current versions and apply vendor-supplied patches as soon as possible. Proactive patch management remains the most effective defense against actively exploited vulnerabilities in enterprise environments.



