
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28711 is a local privilege escalation vulnerability caused by DLL hijacking in Acronis Cyber Protect 17 for Windows. It affects all builds of Acronis Cyber Protect 17 (Windows) prior to build 41186. The vulnerability was published on March 5–6, 2026, with a patch made available by March 11, 2026. It carries a CVSS v3.0 base score of 6.3 (Medium) (Acronis Advisory, Red Hat CVE).
The root cause is an Uncontrolled Search Path Element (CWE-427), which enables DLL search order hijacking (MITRE ATT&CK T1574.001). A low-privileged local attacker can place a malicious DLL in a directory that Acronis Cyber Protect searches before the legitimate DLL location, causing the application to load the attacker-controlled library with elevated privileges. Exploitation requires local access and low privileges, but no user interaction, and the attack complexity is rated High (Acronis Advisory, Red Hat CVE).
Successful exploitation allows a low-privileged local attacker to escalate privileges on the affected Windows system, resulting in high confidentiality and high integrity impact — meaning the attacker can access sensitive data and modify system resources. Availability is not directly impacted. The scope is limited to the affected system (unchanged scope), but privilege escalation could enable further lateral movement or persistence within the environment (Acronis Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local authenticated access and high attack complexity, limiting the practical attacker pool (Acronis Advisory, Red Hat CVE).
AcronisCyberProtect.exe or related services) loading DLLs from unusual or user-writable paths (detectable via Process Monitor or Sysmon Event ID 7).Acronis has released a patch in Acronis Cyber Protect 17 build 41186 for Windows, which resolves this vulnerability. Users should upgrade to build 41186 or later as the primary remediation. As a workaround prior to patching, administrators can restrict write permissions on directories within and adjacent to the Acronis Cyber Protect installation path to prevent low-privileged users from placing malicious DLLs (Acronis Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."