Acronis

Acronis

Top 10K site
Bounty

Program Details

Handle
acronis
Managed
No

Response Metrics

Response Time
Less than a day
Bounty Time
1749 days
Resolution Time
6192 days
Response Efficiency
55%

Scope (21 targets)

web: 7 mobile: 5 other: 9

Bounty splitting: Yes

In Scope

  • *-api-*.acronis.com web bounty-eligible
  • *.5nine.com web bounty-eligible
  • *.acronis.com web bounty-eligible
  • *.acronis.work web bounty-eligible
  • *.devicelock.com web bounty-eligible
  • 1118448159 mobile bounty-eligible
  • 1192506963 mobile bounty-eligible
  • 978342143 mobile bounty-eligible
  • Acronis Agent other bounty-eligible
  • Acronis Cloud Manager other bounty-eligible
  • Acronis Cyber Infrastructure other bounty-eligible
  • Acronis Cyber Protect other bounty-eligible
  • Acronis DeviceLock DLP other bounty-eligible
  • Acronis Snap Deploy other bounty-eligible
  • Acronis True Image (formerly Acronis Cyber Protect Home Office) other bounty-eligible
  • Other Acronis Domains other bounty-eligible
  • Other Acronis executables other bounty-eligible
  • account.acronis.com web bounty-eligible
  • beta-cloud.acronis.com web bounty-eligible
  • com.acronis.abc mobile bounty-eligible
  • and 1 more targets

Out of Scope

learn.acronis.com, training.acronis.com

Known Exploited Vulnerabilities 2CVEs

  • CVE-2026-87886BackupSep 16, 20260.3% EPSS

    Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

  • CVE-2023-45249Cyber Infrastructure (ACI)Jul 29, 202453.3% EPSS

    Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.

security.txt

Contact
mailto:[email protected], https://hackerone.com/acronis/
Hiring
https://www.acronis.com/en-us/careers/
View raw security.txt →