LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

Project Subscriptions

Vendors Products
Litespeed Technologies Subscribe
Cpanel Plugin Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to the LiteSpeed WHM PlugIn v5.3.2.0 or higher (which includes the cPanel PlugIn v2.4.8).


Workaround

Disable the cPanel PlugIn for LiteSpeed

History

Sun, 14 Jun 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Litespeed Technologies
Litespeed Technologies cpanel Plugin
Vendors & Products Litespeed Technologies
Litespeed Technologies cpanel Plugin

Sun, 14 Jun 2026 05:30:00 +0000

Type Values Removed Values Added
Title Symlink Manipulation Allowing Remote Code Execution in LiteSpeed cPanel Plugin

Sun, 14 Jun 2026 04:00:00 +0000

Type Values Removed Values Added
Description LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-14T03:23:12.863Z

Reserved: 2026-06-14T03:23:12.439Z

Link: CVE-2026-54420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-14T04:16:28.630

Modified: 2026-06-14T04:16:28.630

Link: CVE-2026-54420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-14T06:15:06Z

Weaknesses