CVE-2024-8767 is a critical vulnerability allowing sensitive data disclosure and manipulation due to excessive privilege assignments in Acronis Backup plugins for cPanel & WHM, Plesk, and DirectAdmin on Linux, affecting versions before builds 619, 555, and 147 respectively. With a CVSS score of 9.9, this vulnerability is easily exploitable over the network with low privileges and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Acronis | Acronis Backup Extension For Plesk | >= unspecified, < 555CNA affecteddefault unaffected | |
| Acronis | Acronis Backup Plugin For DirectAdmin | >= unspecified, < 147CNA affecteddefault unaffected | |
| Acronis | Acronis Backup Plugin For CPanel & WHM | >= unspecified, < 619CNA affecteddefault unaffected |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.