Acronis Warns of Active Exploitation in Linux Backup Plugin Vulnerability
AI-generated from multiple sources. Verify before acting on this reporting.
ZURICH (AP) — Acronis disclosed on Monday that a high-severity security vulnerability in its backup plugin for Linux-based web hosting platforms is being actively exploited by attackers. The flaw, which allows for local privilege escalation, affects the company's integration with cPanel, WebHost Manager (WHM), and Plesk.
The Swiss data protection firm announced the discovery late Monday evening, urging administrators to apply patches immediately. The vulnerability enables an attacker who has gained initial access to a system to elevate their privileges to root level, granting them full control over the affected server. Once elevated, malicious actors can potentially access sensitive customer data, modify system configurations, or deploy ransomware.
Acronis stated that the exploit is currently in the wild, indicating that threat actors are already targeting unpatched systems. The company has released an emergency update to address the issue across all supported versions of its backup plugin for Linux environments. Administrators running cPanel, WHM, or Plesk are advised to update their Acronis plugins as soon as possible to mitigate the risk.
The vulnerability stems from a logic error within the plugin's permission handling mechanism on Linux operating systems. While the specific technical details of the exploit chain were not fully disclosed in the initial advisory to prevent further abuse, Acronis confirmed that the flaw is severe enough to compromise the integrity of entire hosting environments if left unaddressed.
Web hosting providers and system administrators managing servers with these configurations are the primary targets. The widespread use of cPanel, WHM, and Plesk in the shared hosting sector means the potential impact could be significant, affecting thousands of websites hosted on vulnerable infrastructure. Acronis emphasized that the risk is immediate, as the active exploitation suggests that automated scanning tools or targeted attackers have already identified susceptible systems.
The company has not yet provided details regarding the origin of the exploit or whether any specific threat groups are responsible for its deployment. It remains unclear how long the vulnerability existed before it was discovered and actively weaponized. Acronis is currently working with affected hosting providers to assist in patching efforts and monitoring for signs of compromise.
Security researchers note that local privilege escalation vulnerabilities often require an initial foothold on the system, but once exploited, they can lead to total server takeover. The active nature of this threat underscores the critical need for rapid patch management in web hosting environments. As of Monday night, Acronis was continuing to monitor the situation for new developments regarding the scope of the attacks and the emergence of additional variants of the exploit.