Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://security-advisory.acronis.com/advisories/SEC-2410 | vendor advisory |