Vulnerability Intelligence Report
CVE-2024-8767
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:0.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-250 ↗CWE-250
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Acronis | Acronis Backup plugin for cPanel & WHM | unspecified < 619 (affected) |
| Acronis | Acronis Backup extension for Plesk | unspecified < 555 (affected) |
| Acronis | Acronis Backup plugin for DirectAdmin | unspecified < 147 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.476%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Acronis International GmbH · Vendor · Switzerland |
| Reserved | 2024-09-12T20:55:33 |
| Published | 2024-09-17T08:51:28 |
| Last Updated | 2024-09-17T13:43:37 |
Community Chatter & Buzz