CVE-2026-25852: Medium severity Acronis DeviceLock DLP vulnerability
Published Apr 29, 2026
·Updated
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212.
Affected Software
1 affected component
Acronis DeviceLock DLP<9.0.93212
Event History
Apr 29, 2026
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25852?
CVE-2026-25852 has been classified as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2026-25852?
To fix CVE-2026-25852, upgrade to Acronis DeviceLock DLP version 9.0.93212 or later.
3
What impact does CVE-2026-25852 have on Acronis DeviceLock DLP?
CVE-2026-25852 allows an attacker to gain elevated privileges on affected systems, potentially compromising security.
4
What products are affected by CVE-2026-25852?
CVE-2026-25852 affects Acronis DeviceLock DLP for Windows prior to build 9.0.93212.
5
Is there a workaround for CVE-2026-25852 until a fix is applied?
No official workaround has been provided for CVE-2026-25852; it is recommended to apply the available software update.