CVE-2024-8767
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Ba...
Affects 0 products across 6 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Sensitive data disclosure and manipulation vulnerability due to unnecessary privileges assignment in Acronis Backup plugins/extensions for cPanel & WHM, Plesk, and DirectAdmin.
BSID: BS-2024-GLOBAL-226613-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-8767?
What is the CVSS score for CVE-2024-8767?
Is CVE-2024-8767 actively exploited?
How do I remediate CVE-2024-8767?
What systems are affected by CVE-2024-8767?
| CVE ID | CVE-2024-8767 |
|---|---|
| BSID | BS-2024-GLOBAL-226613-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-09-17 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
Source: NIST NVD / MITRE CVE Database
An attacker with access to the affected systems could exploit this vulnerability to gain unauthorized access to sensitive data and manipulate it due to overly permissive privilege assignments.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Acronis | — | — |
| Cpanel | — | — |
| Directadmin | — | — |
| Linux | — | — |
| Plesk | — | — |
| Plugin | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 191373ce82b622948d7995339cc1d3922d5f6951ccc3ca8a84a7b7e1e8fd658fa760b7eb814e1ebe06b2e4a55cfd0d319b125363fa9fa0613ea284dc7a227b9c |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →