CVE-2026-28711
Acronis Cyber Protect vulnerability analysis and mitigation

Overview

CVE-2026-28711 is a local privilege escalation vulnerability caused by DLL hijacking in Acronis Cyber Protect 17 for Windows. It affects all builds of Acronis Cyber Protect 17 (Windows) prior to build 41186. The vulnerability was published on March 5–6, 2026, with a patch made available by March 11, 2026. It carries a CVSS v3.0 base score of 6.3 (Medium) (Acronis Advisory, Red Hat CVE).

Technical details

The root cause is an Uncontrolled Search Path Element (CWE-427), which enables DLL search order hijacking (MITRE ATT&CK T1574.001). A low-privileged local attacker can place a malicious DLL in a directory that Acronis Cyber Protect searches before the legitimate DLL location, causing the application to load the attacker-controlled library with elevated privileges. Exploitation requires local access and low privileges, but no user interaction, and the attack complexity is rated High (Acronis Advisory, Red Hat CVE).

Impact

Successful exploitation allows a low-privileged local attacker to escalate privileges on the affected Windows system, resulting in high confidentiality and high integrity impact — meaning the attacker can access sensitive data and modify system resources. Availability is not directly impacted. The scope is limited to the affected system (unchanged scope), but privilege escalation could enable further lateral movement or persistence within the environment (Acronis Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local authenticated access and high attack complexity, limiting the practical attacker pool (Acronis Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a target Windows system running Acronis Cyber Protect 17 before build 41186 with local user access.
  2. Identify vulnerable DLL search path: Analyze the Acronis Cyber Protect installation to determine which directories are searched for DLLs before the legitimate system or application directories (e.g., using tools like Process Monitor to observe DLL load attempts).
  3. Craft malicious DLL: Create a malicious DLL with the same name as a DLL that Acronis Cyber Protect attempts to load, containing attacker-controlled code (e.g., adding a new privileged user or launching a reverse shell).
  4. Place malicious DLL: Copy the crafted DLL into a directory that the application searches first and that the low-privileged attacker has write access to.
  5. Trigger DLL load: Wait for or trigger the Acronis Cyber Protect service or process to restart or perform an action that causes it to load the DLL, resulting in execution of the malicious code with elevated privileges (Acronis Advisory).

Indicators of compromise

  • File System: Unexpected DLL files placed in non-standard directories within or adjacent to the Acronis Cyber Protect installation path; DLL files with names matching legitimate Acronis or system libraries in user-writable directories.
  • Process: Acronis Cyber Protect processes (e.g., AcronisCyberProtect.exe or related services) loading DLLs from unusual or user-writable paths (detectable via Process Monitor or Sysmon Event ID 7).
  • Logs: Windows Event Logs showing privilege escalation events (e.g., Event ID 4672 – Special privileges assigned to new logon) shortly after Acronis service restarts; Sysmon logs showing image load events from unexpected paths for Acronis processes.
  • Registry: Unexpected modifications to service binary paths or DLL load configurations associated with Acronis Cyber Protect services.

Mitigation and workarounds

Acronis has released a patch in Acronis Cyber Protect 17 build 41186 for Windows, which resolves this vulnerability. Users should upgrade to build 41186 or later as the primary remediation. As a workaround prior to patching, administrators can restrict write permissions on directories within and adjacent to the Acronis Cyber Protect installation path to prevent low-privileged users from placing malicious DLLs (Acronis Advisory).

Additional resources


SourceThis report was generated using AI

Related Acronis Cyber Protect vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28727HIGH7.8
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28725MEDIUM5.5
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28726MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28724MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026
CVE-2026-28723MEDIUM4.3
  • Acronis Cyber Protect logoAcronis Cyber Protect
  • cpe:2.3:a:acronis:cyber_protect
NoYesMar 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management