PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33092 Acronis CVE debrief

A local privilege escalation vulnerability exists in Acronis True Image for macOS due to improper handling of environment variables. The flaw allows an attacker with local access and low privileges to escalate to higher privileges without user interaction, potentially achieving full confidentiality, integrity, and availability impact on affected systems. The vulnerability stems from CWE-15: External Control of System or Configuration Setting, where environment variables are not properly sanitized or validated before use in privileged operations.

Vendor
Acronis
Product
Acronis True Image OEM
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-10
Original CVE updated
2026-05-19
Advisory published
2026-04-10
Advisory updated
2026-05-19

Who should care

macOS system administrators deploying Acronis True Image in enterprise environments; security teams managing endpoint backup solutions; organizations with compliance requirements for privilege separation on macOS workstations.

Technical summary

The vulnerability exists in the macOS implementation of Acronis True Image where environment variables are improperly handled during privileged operations. An attacker with local access can manipulate environment variables to influence the behavior of Acronis processes running with elevated privileges. The attack requires low privileges and no user interaction, with low attack complexity. Successful exploitation yields high impact across confidentiality, integrity, and availability dimensions. The fix involves updated builds that properly sanitize environment variable inputs before use in privileged contexts.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Acronis True Image OEM (macOS) to build 42571 or later
  • Upgrade Acronis True Image (macOS) to build 42902 or later
  • Audit and restrict local user privileges on macOS endpoints running Acronis True Image
  • Monitor for anomalous process executions with elevated privileges originating from Acronis True Image components
  • Review environment variable configurations in Acronis deployment scripts and launch daemons

Evidence notes

CVE published 2026-04-10; NVD record modified 2026-05-19. Vendor advisory SEC-9407 confirms affected product builds. CVSS 3.0 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates local attack vector with low attack complexity and low privileges required, no user interaction needed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-33092 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-33092

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-33092 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33092

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.