Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.3
Acronis Cyber Protect settings can be modified without permission
CVE-2026-28720
Summary
Acronis Cyber Protect versions before build 41186 on Linux and Windows may allow unauthorized users to change settings. This could lead to security misconfigurations or other unintended consequences. Update to version 17 build 41186 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| acronis | cyber_protect | <= 17.0.41186 | – |
Original title
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Original description
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
nvd CVSS3.0
4.3
Vulnerability type
CWE-863
Incorrect Authorization
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026