CVE-2026-28713

Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:acronis:agent:*:*:*:*:*:*:*:*
cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*

History

13 Mar 2026, 16:37

Type Values Removed Values Added
CPE cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*
cpe:2.3:a:acronis:agent:*:*:*:*:*:*:*:*
First Time Acronis
Acronis agent
Acronis cyber Protect
References () https://security-advisory.acronis.com/advisories/SEC-4168 - () https://security-advisory.acronis.com/advisories/SEC-4168 - Vendor Advisory

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Credenciales predeterminadas establecidas para el usuario privilegiado local en el Dispositivo Virtual. Los siguientes productos están afectados: Acronis Cyber Protect Cloud Agent (VMware) antes de la compilación 36943, Acronis Cyber Protect 17 (VMware) antes de la compilación 41186.

06 Mar 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 00:16

Updated : 2026-03-13 16:37


NVD link : CVE-2026-28713

Mitre link : CVE-2026-28713

CVE.ORG link : CVE-2026-28713


JSON object : View

Products Affected

acronis

  • cyber_protect
  • agent
CWE
CWE-1392

Use of Default Credentials