CVE-2025-30410 PUBLISHED

Assigner: Acronis
Reserved: 21.03.2025 Published: 20.02.2026 Updated: 20.02.2026

Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 41800.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Acronis
Product Acronis Cyber Protect Cloud Agent
Versions Default: unaffected
  • affected from unspecified to 39870 (excl.)
Vendor Acronis
Product Acronis Cyber Protect 16
Versions Default: unaffected
  • affected from unspecified to 39938 (excl.)
Vendor Acronis
Product Acronis Cyber Protect 15
Versions Default: unaffected
  • affected from unspecified to 41800 (excl.)

Credits

  • Airbus SecLab (mailto:vuln@airbus.com) finder
  • Quentin Liddell (mailto:vuln@airbus.com) finder
  • Mattéo Ricordeau (mailto:vuln@airbus.com) finder
  • Benoît Camredon (mailto:vuln@airbus.com) finder

References

Problem Types

  • CWE-306 CWE