Acronis Flags Actively Exploited Linux Privilege Escalation Bug in cPanel Backup Plugin
Acronis warned Tuesday that a critical vulnerability in its backup plugin for cPanel, WebHost Manager and Plesk is being actively exploited in the wild.
The flaw is a Linux local‑privilege‑escalation bug that could allow an attacker who already has limited access to a server to elevate to root privileges, giving full control over the system and any hosted websites.
cPanel, WHM and Plesk are among the most widely used control panels for shared‑hosting environments, and Acronis’s backup extension is bundled with many commercial hosting packages. Because these panels often run on Linux distributions that are the default for web servers, the vulnerability potentially impacts a large segment of the hosting market.
The issue was first highlighted by security‑focused outlet BleepingComputer, prompting Acronis to publish an advisory and confirm that the bug can be triggered remotely after a low‑level foothold is obtained. The company has already made a patched version of the plugin available and is urging administrators to update without delay.
Experts recommend that hosting providers apply the update, verify that the plugin version is the latest, and review system logs for any signs of unauthorized activity. In environments where an immediate upgrade is not possible, temporarily disabling the backup module can reduce exposure while a fix is rolled out.
If exploited, the vulnerability could enable attackers to install malware, exfiltrate data, or launch further attacks against customers of the compromised host. The fact that the flaw is being used in active campaigns raises the urgency for rapid remediation across all affected installations.
Acronis says it will continue monitoring the situation and work with the security community to track any new exploitation techniques. Administrators are advised to stay informed through official vendor channels and to adopt a layered security approach that includes regular patching, least‑privilege configurations, and intrusion‑detection tools.
Comments (0)
Be the first to comment.
Join the discussion