CVE-2025-30416
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 ...
Affects 3 products across 3 vendors.
Software does not check whether an authenticated actor has permission for the requested operation.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in Acronis Cyber Protect 16 and 15 allows unauthorized access and manipulation of sensitive data due to missing authorization checks.
BSID: BS-2026-GLOBAL-251576-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-30416?
What is the CVSS score for CVE-2025-30416?
Is CVE-2025-30416 actively exploited?
How do I remediate CVE-2025-30416?
What systems are affected by CVE-2025-30416?
| CVE ID | CVE-2025-30416 |
|---|---|
| BSID | BS-2026-GLOBAL-251576-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-02-20 |
| Last Modified | 2026-03-12 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Source: NIST NVD / MITRE CVE Database
An attacker with network access to the affected Acronis Cyber Protect servers can exploit this vulnerability to gain unauthorized access to sensitive data, potentially leading to data manipulation or disclosure.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Acronis | Cyber Protect | — |
| Linux | Linux Kernel | — |
| Microsoft | Windows | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | cc944fce4ce75d86e0bd0cdeec5f9245f01d54ae766865c075f73e53f7e790eafe354eb3259bdb959d13ea4a3a42e9b0e80ec45bf01d21165af44f4b63bcab38 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →