VendorsAcroniscyber_protectany version
Vulnerabilities

Acronis Cyber Protect any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

71CVEs
CVE-2026-28711
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
Published 2026-03-05 · Analyzed
6.3EPSS 0.001
CVE-2020-35664
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.
Published 2021-02-22 · Modified
6.1EPSS 0.007
CVE-2021-44201
Cross-site scripting (XSS) was possible in notification pop-ups
Published 2021-11-29 · Modified
6.1EPSS 0.006
CVE-2021-38087
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
Published 2021-08-12 · Modified
6.1EPSS 0.006
CVE-2022-30992
Open redirect via user-controlled query parameter
Published 2022-05-18 · Modified
6.1EPSS 0.006
CVE-2022-30991
HTML injection via report name
Published 2022-05-18 · Modified
6.1EPSS 0.006
CVE-2023-48682
Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
Published 2024-02-27 · Analyzed
6.1EPSS 0.003
CVE-2023-48681
Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
Published 2024-02-27 · Analyzed
6.1EPSS 0.003
CVE-2024-55541
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
Published 2025-01-02 · Analyzed
6.1EPSS 0.003
CVE-2021-44199
DLL hijacking could lead to denial of service
Published 2021-11-29 · Modified
5.5EPSS 0.002
CVE-2023-48680
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.
Published 2024-02-27 · Analyzed
5.5EPSS 0.002
CVE-2026-28725
Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
5.5EPSS 0.002
CVE-2023-48678
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
Published 2024-02-27 · Analyzed
5.5EPSS 0.002
CVE-2021-44203
Stored cross-site scripting (XSS) was possible in protection plan details
Published 2021-11-29 · Modified
5.4EPSS 0.005
CVE-2021-44202
Stored cross-site scripting (XSS) was possible in activity details
Published 2021-11-29 · Modified
5.4EPSS 0.005
CVE-2021-44200
Self cross-site scripting (XSS) was possible on devices page
Published 2021-11-29 · Modified
5.4EPSS 0.005
CVE-2023-48679
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
Published 2024-02-27 · Analyzed
5.4EPSS 0.003
CVE-2023-44205
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
5.3EPSS 0.006
CVE-2026-28717
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
Published 2026-03-05 · Analyzed
5.0EPSS 0.001
CVE-2026-28714
Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.8EPSS 0.002
CVE-2025-30413
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.4EPSS 0.002
CVE-2026-28716
Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.4EPSS 0.001
CVE-2026-28724
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.3EPSS 0.003
CVE-2026-28726
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.3EPSS 0.003
CVE-2026-28709
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.3EPSS 0.003
CVE-2026-28719
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.3EPSS 0.003
CVE-2026-28720
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.3EPSS 0.003
CVE-2026-28723
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
4.3EPSS 0.003
CVE-2024-49382
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Published 2024-10-15 · Analyzed
4.3EPSS 0.002
CVE-2024-49383
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Published 2024-10-15 · Analyzed
4.3EPSS 0.002
CVE-2024-49384
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Published 2024-10-15 · Analyzed
4.3EPSS 0.002
← Prev2 / 2