CVE-2026-28727

Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:acronis:agent:*:*:*:*:*:*:*:*
cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

02 Apr 2026, 18:16

Type Values Removed Values Added
Summary (en) Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124. (en) Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.

13 Mar 2026, 16:31

Type Values Removed Values Added
CPE cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*
cpe:2.3:a:acronis:agent:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
References () https://security-advisory.acronis.com/advisories/SEC-9408 - () https://security-advisory.acronis.com/advisories/SEC-9408 - Vendor Advisory
First Time Acronis agent
Acronis
Apple
Apple macos
Acronis cyber Protect

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Escalada de privilegios local debido a permisos inseguros de socket Unix. Los siguientes productos están afectados: Acronis Cyber Protect 17 (macOS) anterior a la compilación 41186, Acronis Cyber Protect Cloud Agent (macOS) anterior a la compilación 41124.

06 Mar 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 00:16

Updated : 2026-04-02 18:16


NVD link : CVE-2026-28727

Mitre link : CVE-2026-28727

CVE.ORG link : CVE-2026-28727


JSON object : View

Products Affected

acronis

  • cyber_protect
  • agent

apple

  • macos
CWE
CWE-276

Incorrect Default Permissions