CVE-2026-28727 Details
Description
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.
A local privilege escalation vulnerability has been identified in Acronis Cyber Protect 17 for macOS, prior to build 41186, and in Acronis Cyber Protect Cloud Agent for macOS, prior to build 41124. This vulnerability arises from insecure permissions on Unix sockets, which could potentially be exploited to gain elevated privileges.
Users can update to Acronis Cyber Protect 17 build 41186 or Acronis Cyber Protect Cloud Agent build 41124 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security-advisory.acronis.com/advisories/SEC-9408 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| acronis agent | < c25.10 |
CPE
Remediation
| |
| acronis cyber protect | < 17.0.41186 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Mar 13, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | [email protected] |