CVE-2025-30411
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.69%
- CWE
- CWE-1390
- Published
- 2026-02-20
- Last modified
- 2026-03-12
Affected products
- Acronis Acronis Cyber Protect 16
- Acronis Acronis Cyber Protect 15
Weakness type
Related vulnerabilities
- CVE-2025-40552 — SolarWinds Web Help Desk Authentication Bypass Vulnerability
- CVE-2025-40554 — SolarWinds Web Help Desk Authentication Bypass Vulnerability
- CVE-2025-30412 — Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
- CVE-2024-54092 — A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device K
- CVE-2025-39596 — WordPress Quentn WP <= 1.2.8 - Privilege Escalation Vulnerability
- CVE-2025-1387 — Learning Digital Orca HCM - Improper Authentication
- CVE-2025-12871 — aEnrich|a+HRD - Authentication Abuse
- CVE-2025-12870 — aEnrich|eHRD - Authentication Abuse