CVE-2026-42061: High severity Acronis DeviceLock DLP vulnerability
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acronis DeviceLock DLP (Windows)to a version that resolves this vulnerability.Fixed in 9.0.15051.93227
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42061?
CVE-2026-42061 has a severity rating of high, with a CVSS score of 7.3.
How do I fix CVE-2026-42061?
To mitigate CVE-2026-42061, upgrade Acronis DeviceLock DLP to version 9.0.15051.93227 or later.
What causes CVE-2026-42061?
CVE-2026-42061 is caused by excessive permissions assigned to child processes, leading to local privilege escalation.
Which products are affected by CVE-2026-42061?
CVE-2026-42061 affects Acronis DeviceLock DLP for Windows prior to build 9.0.15051.93227.
Is CVE-2026-42061 easy to exploit?
CVE-2026-42061 can be exploited locally, making it relatively easy for an attacker with user access to escalate privileges.