Home/Product/acronis cyber protect
Product

acronis cyber protect

86 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-28727
< 17.0.41186
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17
7.8HIGH
CVE-2026-28726
< 17.0.41186
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Li
4.3MEDIUM
CVE-2026-28725
< 17.0.41186
Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis
5.5MEDIUM
CVE-2026-28724
< 17.0.41186
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect
4.3MEDIUM
CVE-2026-28723
< 17.0.41186
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Li
4.3MEDIUM
CVE-2026-28722
< 17.0.41186
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Wind
7.3HIGH
CVE-2026-28721
< 17.0.41186
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Wind
7.3HIGH
CVE-2026-28720
< 17.0.41186
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber
4.3MEDIUM
CVE-2026-28719
< 17.0.41186
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protec
4.3MEDIUM
CVE-2026-28718
< 17.0.41186
Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyb
7.5HIGH
CVE-2026-28717
< 17.0.41186
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (W
5.0MEDIUM
CVE-2026-28716
< 17.0.41186
Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber P
4.4MEDIUM
CVE-2026-28715
< 17.0.41186
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect
6.5MEDIUM
CVE-2026-28714
< 17.0.41186
Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux
4.8MEDIUM
CVE-2026-28713
< 17.0.41186
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect
7.1HIGH
CVE-2026-28712
< 17.0.41186
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Wind
6.3MEDIUM
CVE-2026-28711
< 17.0.41186
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Wind
6.3MEDIUM
CVE-2026-28710
< 17.0.41186
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyb
9.8CRITICAL
CVE-2026-28709
< 17.0.41186
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protec
4.3MEDIUM
CVE-2025-30413
< 17.0.41186
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect C
4.4MEDIUM
CVE-2025-11791
< 17.0.41186
Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: A
7.1HIGH
CVE-2025-30416
all versions
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protec
10.0CRITICAL
CVE-2025-30412
all versions
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Prot
10.0CRITICAL
CVE-2025-30411
all versions
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Prot
10.0CRITICAL
CVE-2024-55543
<= 15
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Wind
7.8HIGH
CVE-2024-55541
<= 15
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affect
6.1MEDIUM
CVE-2024-55540
<= 15
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Wind
7.8HIGH
CVE-2024-49388
<= 15
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (L
9.1CRITICAL
CVE-2024-49387
<= 15
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Prot
7.5HIGH
CVE-2024-49384
<= 15
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affect
4.3MEDIUM
CVE-2024-49383
<= 15
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affecte
4.3MEDIUM
CVE-2024-49382
<= 15
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affect
4.3MEDIUM
CVE-2022-45449
< 15
Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acron
6.5MEDIUM
CVE-2023-48682
< 16
Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux
5.4MEDIUM
CVE-2023-48681
< 16
Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Pr
6.1MEDIUM
CVE-2023-48680
< 16
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis C
5.5MEDIUM
CVE-2023-48679
< 16
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affect
5.4MEDIUM
CVE-2023-48678
< 16
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16
5.5MEDIUM
CVE-2023-44207
< 15
Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cyber Protec
5.4MEDIUM
CVE-2023-44206
< 15
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cybe
9.1CRITICAL
CVE-2023-44205
< 15
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Lin
5.3MEDIUM
CVE-2023-44161
< 15
Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 1
6.5MEDIUM
CVE-2023-44160
< 15
Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 1
6.5MEDIUM
CVE-2023-44159
< 15
Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis C
7.5HIGH
CVE-2023-44158
< 15
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Prote
7.5HIGH
CVE-2023-44157
< 15
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Wind
7.8HIGH
CVE-2023-44156
< 15
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windo
7.5HIGH
CVE-2023-44155
< 15
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) befor
7.5HIGH
CVE-2023-44154
< 15
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cybe
8.1HIGH
CVE-2023-44153
< 15
Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected:
7.5HIGH
CVE-2023-44152
< 15
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyb
9.1CRITICAL
CVE-2023-41749
all versions
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis A
7.5HIGH
CVE-2023-41745
all versions
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis A
5.5MEDIUM
CVE-2023-41744
all versions
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (
7.8HIGH
CVE-2023-41743
all versions
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyb
7.8HIGH
CVE-2023-41742
all versions
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux,
7.5HIGH
CVE-2022-45451
all versions
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyb
7.8HIGH
CVE-2022-45459
< 15
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows
7.5HIGH
CVE-2022-45458
< 15
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: A
7.5HIGH
CVE-2022-45457
< 15
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: A
7.5HIGH
CVE-2022-45453
< 15
TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30
7.5HIGH
CVE-2022-45452
< 15
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before
7.8HIGH
CVE-2022-45450
< 15
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agen
7.5HIGH
CVE-2022-3405
all versions
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products
8.8HIGH
CVE-2022-30995
all versions
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Wi
7.5HIGH
CVE-2022-45455
all versions
Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Ho
7.8HIGH
CVE-2022-45454
all versions
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows)
7.5HIGH
CVE-2022-30994
< 15
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before bu
7.5HIGH
CVE-2022-30993
< 15
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) be
7.5HIGH
CVE-2022-30992
< 15
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows)
6.1MEDIUM
CVE-2022-30991
< 15
HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
6.1MEDIUM
CVE-2022-30990
< 15
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15
7.5HIGH
CVE-2022-24113
all versions
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis
7.8HIGH
CVE-2021-44204
all versions
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cybe
7.8HIGH
CVE-2021-44203
< 15
Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Prot
5.4MEDIUM
CVE-2021-44202
< 15
Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15
5.4MEDIUM
CVE-2021-44201
< 15
Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Wi
6.1MEDIUM
CVE-2021-44200
< 15
Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windo
5.4MEDIUM
CVE-2021-44199
< 15
DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before buil
5.5MEDIUM
CVE-2021-44198
< 15
DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) be
7.8HIGH
CVE-2021-38088
< 15
Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
7.8HIGH
CVE-2021-38087
< 15
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
6.1MEDIUM
CVE-2021-38086
< 15
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privile
7.8HIGH
CVE-2020-35664
< 15
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the consol
6.1MEDIUM
CVE-2020-35556
< 15
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigu
7.5HIGH
CVE-2020-10138
< 15
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirector
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin