CVE-2025-30410
Acronis Cyber Protect vulnerability analysis and mitigation

Overview

CVE-2025-30410 is a missing authentication vulnerability in Acronis Cyber Protect products that enables sensitive data disclosure and manipulation by unauthenticated remote attackers. It affects Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, and Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 41800. The vulnerability carries a CVSS v3.0 base score of 9.8 (Critical) (Acronis Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning certain critical functions or endpoints within the Acronis agent/product are accessible without requiring any authentication. An unauthenticated remote attacker can send network requests directly to these unprotected endpoints, bypassing access controls entirely. No user interaction or privileges are required, and attack complexity is low, making this straightforward to exploit over the network (Acronis Advisory, The Hacker Wire).

Impact

Successful exploitation allows an unauthenticated attacker to both disclose and manipulate sensitive data managed by the Acronis Cyber Protect agent, with full impact to confidentiality, integrity, and availability. Given that Acronis Cyber Protect handles backup, recovery, and endpoint security data, exploitation could expose backup credentials, configuration data, and protected files, while also enabling tampering with backup jobs or security policies. The cross-platform scope (Linux, macOS, Windows) and the agent's typical deployment in enterprise environments amplify the risk of lateral movement and data exfiltration (Acronis Advisory, Heise).

Exploitability

No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. CVE-2025-30410 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. However, the unauthenticated, network-accessible nature of the flaw (no privileges, no user interaction required) makes it highly attractive for opportunistic attackers targeting enterprise backup infrastructure (Acronis Advisory, The Hacker Wire).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible hosts running Acronis Cyber Protect Cloud Agent, Cyber Protect 16, or Cyber Protect 15 using tools like Shodan, Censys, or internal network scanning. Look for default Acronis agent ports (e.g., TCP 9876 or other management ports).
  2. Version fingerprinting: Confirm the target is running a vulnerable build (Cloud Agent < 39870, Cyber Protect 16 < 39938, Cyber Protect 15 < 41800) by querying exposed service banners or API endpoints.
  3. Access unauthenticated endpoint: Send unauthenticated HTTP/HTTPS requests directly to the critical function endpoints exposed by the Acronis agent, bypassing any authentication requirement due to the CWE-306 flaw.
  4. Data disclosure: Retrieve sensitive configuration data, credentials, backup metadata, or other protected information returned by the unprotected endpoint.
  5. Data manipulation: Issue unauthenticated commands or modify configurations (e.g., alter backup schedules, disable protection policies, or inject malicious data) through the same unprotected interface (Acronis Advisory, The Hacker Wire).

Indicators of compromise

  • Network: Unexpected unauthenticated HTTP/HTTPS requests to Acronis agent management ports (e.g., TCP 9876) from external or unusual internal IP addresses; anomalous outbound connections from hosts running Acronis agents.
  • Logs: Acronis agent logs showing access to sensitive API endpoints without authentication tokens or session identifiers; repeated requests to critical function endpoints from a single source IP.
  • File System: Unexpected changes to Acronis configuration files or backup job definitions; new or modified scheduled tasks/cron jobs related to Acronis processes.
  • Process: Unusual child processes spawned by Acronis agent services; unexpected data transfers initiated by the Acronis agent process (Acronis Advisory).

Mitigation and workarounds

Acronis has released patched builds addressing this vulnerability: Acronis Cyber Protect Cloud Agent build 39870 or later, Acronis Cyber Protect 16 build 39938 or later, and Acronis Cyber Protect 15 build 41800 or later. Organizations should update all affected deployments immediately. As a temporary workaround, restrict network access to Acronis agent management ports using firewall rules to limit exposure to trusted hosts only, and monitor for anomalous unauthenticated access attempts (Acronis Advisory, Heise).

Community reactions

The vulnerability received coverage from security news outlets including Heise and The Hacker Wire, which highlighted the critical unauthenticated data access risk in widely deployed enterprise backup software. Community discussion appeared on forums such as MalwareTips and security blogs, noting the severity of the flaw given Acronis's broad enterprise deployment. Social media posts on Mastodon and Bluesky from security-focused accounts amplified awareness of the advisory (Heise, The Hacker Wire, MalwareTips).

Additional resources


SourceThis report was generated using AI

Related Acronis Cyber Protect vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28727HIGH7.8
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28725MEDIUM5.5
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28726MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28724MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28723MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management