Acronis Backup: "requires local access" — and that access is what you sell your customers
On 15 September Acronis published a one-sentence advisory: local privilege escalation through insecure file permissions in its backup plugin for cPanel and Plesk, CVSS 7.8, exploited in targeted attacks. A "local" 7.8 is exactly the CVE almost every patching queue pushes to next week. On a machine with a single administrator, that call is defensible. On a server where every customer gets their own system user, the requirement for "local access with low privileges" is not describing a barrier: it is describing your business model.