CVE-2024-8767

CRITICAL

Acronis Backup - Info Disclosure

Title source: llm
STIX 2.1

Description

Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.

Scores

CVSS v3 9.9
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Products (3)
Acronis/Acronis Backup extension for Plesk unspecified - 555
Acronis/Acronis Backup plugin for cPanel & WHM unspecified - 619
Acronis/Acronis Backup plugin for DirectAdmin unspecified - 147
Published Sep 17, 2024
Tracked Since Feb 18, 2026