CVE-2025-30412
Acronis Cyber Protect vulnerability analysis and mitigation

Overview

CVE-2025-30412 is a critical improper authentication vulnerability in Acronis Cyber Protect that enables unauthenticated remote attackers to disclose and manipulate sensitive data. It affects Acronis Cyber Protect 16 (Linux, Windows) before build 39938 and Acronis Cyber Protect 15 (Linux, Windows) before build 41800. The vulnerability was published on February 20, 2026, with a patch advisory released by Acronis. It carries a CVSS v3.0 base score of 10.0 (Critical) (Acronis Advisory, Red Hat CVE).

Technical details

The root cause is improper authentication (CWE-287), where the affected Acronis Cyber Protect components fail to adequately verify the identity of requestors before granting access to sensitive operations. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity — making it trivially exploitable by any unauthenticated remote attacker. The vulnerability's changed scope indicates that a successful exploit can impact resources beyond the directly vulnerable component, such as backup data stores, system configurations, and managed endpoints (Acronis Advisory, Red Hat CVE).

Impact

Successful exploitation allows an unauthenticated attacker to disclose sensitive data (confidentiality impact: HIGH), manipulate data integrity (integrity impact: HIGH), and potentially cause denial of service (availability impact: HIGH). Because the scope is changed, the attacker may be able to affect resources beyond the Cyber Protect management component itself, including backup archives, protected endpoint data, and critical system configurations. This could facilitate unauthorized access to business-critical backup data and enable further lateral movement within the protected environment (Acronis Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Acronis Advisory). The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the CVSS 10.0 score and zero-authentication requirement make it a high-priority target if exploitation techniques become public.

Mitigation and workarounds

Acronis has released patches addressing this vulnerability. Organizations should update Acronis Cyber Protect 16 to build 39938 or later, and Acronis Cyber Protect 15 to build 41800 or later, on both Linux and Windows deployments. Given the critical CVSS 10.0 score and zero-authentication requirement, patching should be treated as an urgent priority. As an interim measure, restricting network access to the Cyber Protect management interface to trusted IP ranges can reduce exposure until patching is complete (Acronis Advisory).

Community reactions

The vulnerability received coverage from security news outlets including Heise and The Hacker Wire, which highlighted the critical severity of the flaw alongside other Acronis Cyber Protect vulnerabilities disclosed around the same time (Heise, The Hacker Wire). Community forums such as MalwareTips also discussed the risk to Linux and Windows systems. No significant public researcher commentary or vendor statements beyond the official advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related Acronis Cyber Protect vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28727HIGH7.8
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28725MEDIUM5.5
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28726MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28724MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28723MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management