Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

A Critical Vulnerability in cPanel’s Backup Plugin Exposes Thousands of Websites to Hackers

Thousands of websites are potentially vulnerable to targeted attacks, following the discovery of a critical flaw in Acronis’ cPanel backup plugin. This vulnerability allows attackers to gain unauthorized access to sensitive data and systems, compromising the security posture of affected sites.

The issue lies in the way the backup plugin handles authentication tokens, which can be manipulated by malicious actors to escalate privileges and bypass security controls. By exploiting this weakness, hackers can gain unfettered access to system files, configuration settings, and other sensitive areas. This is particularly concerning given that many website administrators rely on automated backups to ensure business continuity in case of data loss or server crashes.

Acronis’ cPanel backup plugin is widely used across various industries, including e-commerce, finance, and healthcare. It’s estimated that tens of thousands of websites are at risk, although the exact number remains unknown. What’s more alarming is that attackers have already begun targeting vulnerable sites, taking advantage of the vulnerability to launch targeted attacks.

The exploitation of this vulnerability typically involves an attacker manipulating authentication tokens through cross-domain privilege escalation techniques. This allows them to traverse security boundaries and access sensitive areas without being detected. The fact that this vulnerability has been actively exploited in real-world attacks underscores the need for website administrators to take immediate action to mitigate the risk.

The exposure of identity data, including login credentials and system information, plays a significant role in these targeted attacks. By exploiting vulnerabilities like this one, attackers can create a pathway to sensitive areas, often referred to as “breach routes.” These pathways allow hackers to navigate through security controls undetected, making it increasingly difficult for administrators to detect the intrusion.

To stay ahead of such threats, website administrators and security teams must prioritize patching vulnerable plugins and ensuring that backup configurations are secure. Regular system audits and monitoring can also help identify potential weaknesses before they’re exploited by attackers.


Source: The Hacker News — 2026-09-16