Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.4

Acronis Agent Fails to Delete Credentials After Plan Revocation

CVE-2025-30413
Summary

Acronis Cyber Protect Cloud Agent and Cyber Protect 17 for Linux, macOS, and Windows may store old credentials even after a plan is revoked, potentially leaving sensitive information accessible. This could allow unauthorized access to your system. Update your Acronis Agent to the latest version to resolve this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
acronis agent <= c25.07
acronis cyber_protect <= 17.0.41186
Original title
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cybe...
Original description
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.
nvd CVSS3.0 4.4
Vulnerability type
CWE-732 Incorrect Permission Assignment for Critical Resource
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026