CVE-2026-28727 describes a local privilege escalation vulnerability affecting Acronis Cyber Protect 17 (macOS) before build 41186 and Acronis Cyber Protect Cloud Agent (macOS) before build 41124, stemming from insecure Unix socket permissions. This high-severity vulnerability (CVSS 7.8) allows a local attacker with low privileges to achieve full compromise of confidentiality, integrity, and availability with low attack complexity. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog, indicating no active exploitation. While it has received minimal community discussion, its EPSS score suggests a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< c25.10CPE matchmatch criteria | cpe:2.3:a:acronis:agent:*:*:*:*:*:*:*:* | ||
< 17.0.41186CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.