Security Vulnerability Report
中文
CVE-2026-0705 CVSS 6.7 MEDIUM

CVE-2026-0705

Published: 2026-01-27 17:16:10
Last Modified: 2026-04-15 00:35:42

Description

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.4.25342.354.

CVSS Details

CVSS Score
6.7
Severity
MEDIUM
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Acronis Cloud Manager (Windows) < build 6.4.25342.354

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
#!/usr/bin/env python3 """ CVE-2026-0705 PoC - Acronis Cloud Manager Permission Check This script checks for insecure folder permissions on Acronis Cloud Manager installation. Note: Requires administrator privileges to run. """ import os import sys import subprocess import re def check_acl(path): """Check folder permissions using icacls command""" try: result = subprocess.run( ['icacls', path], capture_output=True, text=True, timeout=30 ) return result.stdout except Exception as e: return f"Error checking ACL: {e}" def main(): acronis_paths = [ r"C:\Program Files\Acronis", r"C:\Program Files (x86)\Acronis", r"C:\ProgramData\Acronis" ] print("=" * 60) print("CVE-2026-0705 - Acronis Cloud Manager Permission Check") print("=" * 60) vulnerable = False for path in acronis_paths: if os.path.exists(path): print(f"\n[+] Checking: {path}") acl_output = check_acl(path) # Check if Users group has write permissions if re.search(r'Users.*:(.*)W', acl_output) or re.search(r'BUILTIN\\Users.*:(.*)W', acl_output): print(f"[VULNERABLE] Insecure permissions detected!") print(f"Users group has WRITE permissions on {path}") vulnerable = True else: print(f"[OK] Permissions appear secure") print(f"\nACL Output:\n{acl_output}") if vulnerable: print("\n[!] System is VULNERABLE to CVE-2026-0705") print("[!] Recommendation: Update Acronis Cloud Manager to build >= 6.4.25342.354") return 1 else: print("\n[+] System does not appear to be vulnerable") return 0 if __name__ == "__main__": sys.exit(main())

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-0705", "sourceIdentifier": "[email protected]", "published": "2026-01-27T17:16:10.173", "lastModified": "2026-04-15T00:35:42.020", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.4.25342.354."}, {"lang": "es", "value": "Escalada de privilegios local debido a permisos de carpeta inseguros. Los siguientes productos están afectados: Acronis Cloud Manager (Windows) anterior a la compilación 6.4.25342.354."}], "metrics": {"cvssMetricV30": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 0.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-276"}]}], "references": [{"url": "https://security-advisory.acronis.com/advisories/SEC-7316", "source": "[email protected]"}]}}