CVE-2025-30411 PUBLISHED

Assigner: Acronis
Reserved: 21.03.2025 Published: 20.02.2026 Updated: 20.02.2026

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Acronis
Product Acronis Cyber Protect 16
Versions Default: unaffected
  • affected from unspecified to 39938 (excl.)
Vendor Acronis
Product Acronis Cyber Protect 15
Versions Default: unaffected
  • affected from unspecified to 41800 (excl.)

Credits

  • Airbus SecLab (mailto:vuln@airbus.com) finder
  • Quentin Liddell (mailto:vuln@airbus.com) finder
  • Mattéo Ricordeau (mailto:vuln@airbus.com) finder
  • Benoît Camredon (mailto:vuln@airbus.com) finder

References

Problem Types

  • CWE-1390 CWE