Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.4
Acronis Agent: Credentials not deleted after plan revocation
CVE-2025-11790
Summary
A security issue exists in the Acronis Cyber Protect Cloud Agent. If a plan is revoked, credentials may not be properly deleted, potentially leaving access to sensitive data. Update to build 41124 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| acronis | agent | <= c25.10 | – |
Original title
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
Original description
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
nvd CVSS3.0
4.4
Vulnerability type
CWE-732
Incorrect Permission Assignment for Critical Resource
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026