Description
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 41800.
Problem types
Product status
Any version before 39870
Any version before 39938
Any version before 41800
Credits
Airbus SecLab (mailto:vuln@airbus.com)
Quentin Liddell (mailto:vuln@airbus.com)
Mattéo Ricordeau (mailto:vuln@airbus.com)
Benoît Camredon (mailto:vuln@airbus.com)
References
security-advisory.acronis.com/advisories/SEC-8641 (SEC-8641)