Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.3

Acronis Cyber Protect settings can be modified without permission

CVE-2026-28720
Summary

Acronis Cyber Protect versions before build 41186 on Linux and Windows may allow unauthorized users to change settings. This could lead to security misconfigurations or other unintended consequences. Update to version 17 build 41186 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
acronis cyber_protect <= 17.0.41186 –
Original title
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Original description
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
nvd CVSS3.0 4.3
Vulnerability type
CWE-863 Incorrect Authorization
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026