Improper privilege management in Acronis products - CVE-2025-7779
Published: October 1, 2026
Vulnerability identifier: #VU153065
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7779
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to insecure XPC service configuration. A local user can escalate privileges.
Affected software
Acronis True Image for Western Digital (macOS)
Acronis True Image for SanDisk (macOS)
Acronis True Image (macOS)
Acronis True Image OEM (macOS)
Acronis True Image for SanDisk (macOS)
Acronis True Image (macOS)
Acronis True Image OEM (macOS)
How to mitigate CVE-2025-7779
Install updates from vendor's website.
Acronis True Image for Western Digital (macOS) - update to build 42197
Acronis True Image for SanDisk (macOS) - update to build 42198
Acronis True Image (macOS) - update to build 42389
Acronis True Image OEM (macOS) - update to build 42571
Acronis True Image for SanDisk (macOS) - update to build 42198
Acronis True Image (macOS) - update to build 42389
Acronis True Image OEM (macOS) - update to build 42571