Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.4

Acronis Agent: Credentials not deleted after plan revocation

CVE-2025-11790
Summary

A security issue exists in the Acronis Cyber Protect Cloud Agent. If a plan is revoked, credentials may not be properly deleted, potentially leaving access to sensitive data. Update to build 41124 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
acronis agent <= c25.10 –
Original title
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
Original description
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
nvd CVSS3.0 4.4
Vulnerability type
CWE-732 Incorrect Permission Assignment for Critical Resource
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026