CVE-2025-11790: Medium severity Acronis Cyber Protect Cloud Agent vulnerability
Published Mar 5, 2026
·Updated
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
Affected Software
5 affected components
Acronis Cyber Protect Cloud Agent<41124
All of the following
Acronis Agent<c25.10
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Mar 5, 2026
CVE Published
via MITRE·11:47 PM
Data Sourced
via MITRE·11:47 PM
DescriptionSeverityWeakness
Mar 6, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11790?
CVE-2025-11790 is considered a moderate severity vulnerability due to the risk of credential exposure.
2
How do I fix CVE-2025-11790?
To fix CVE-2025-11790, upgrade the Acronis Cyber Protect Cloud Agent to build 41124 or later.
3
What products are affected by CVE-2025-11790?
CVE-2025-11790 affects Acronis Cyber Protect Cloud Agent on Linux, macOS, and Windows before build 41124.
4
What happens if credentials are not deleted in CVE-2025-11790?
If credentials are not deleted, it may lead to unauthorized access and increased security risks for affected systems.
5
Is there a workaround for CVE-2025-11790?
Currently, the recommended solution is to update to the latest version as there are no known workarounds for CVE-2025-11790.