← Vulnerability feed

Vulnerability record · CVE-2026-54420 · published 14 June 2026

CVE-2026-54420: LiteSpeed cPanel plugin symlink following on shared hosting

Litespeedtech · Litespeed Cpanel Plugin

The LiteSpeed cPanel plugin before 2.4.8 (and LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks supplied by a user who has FTP or web shell access on a shared hosting server running CloudLinux/CageFS. Because the flaw crosses a security boundary on shared infrastructure, a low-privileged tenant can affect files outside their own account. It was exploited in the wild in May 2026 and added to CISA KEV.

8.5 CVSS 3.1 High CISA KEV since 15 Jun 2026 EPSS 0.81% · top 44.9% CWE-61 · CWE-61
8.5CVSS 3.1 base score
0.81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
23 Jul 2026Last modified by NVD

Description

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV with a near-term remediation deadline, despite a modest CVSS base score of 8.5 and low EPSS.

What it is

The LiteSpeed cPanel plugin before 2.4.8 (and LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks supplied by a user who has FTP or web shell access on a shared hosting server running CloudLinux/CageFS. Because the flaw crosses a security boundary on shared infrastructure, a low-privileged tenant can affect files outside their own account. It was exploited in the wild in May 2026 and added to CISA KEV.

Impact

An attacker with FTP or web shell access can follow attacker-controlled symlinks to read or write files outside their hosting account, gaining high confidentiality, integrity and availability impact on other tenants or the host. The scope change in the CVSS vector reflects that the compromise can extend beyond the vulnerable component.

Attack surface

Reachable over the network through the cPanel/WHM plugin interface, but it requires the attacker to already hold a low-privileged account with FTP or web shell access on the shared server. No user interaction is needed; the vector is AV:N/AC:H/PR:L/UI:N/S:C.

Exploitation

Listed in CISA KEV with a due date of 2026-06-18 and described as exploited in the wild in May 2026, so active exploitation is confirmed. EPSS is low at 0.01439 (71.8th percentile), which understates the risk given the KEV entry.

What to do

  • Update the LiteSpeed cPanel plugin to 2.4.8 or later and the LiteSpeed WHM PlugIn to 5.3.2.0 or later, per the vendor advisory.
  • If patching cannot be completed by the CISA due date, apply the vendor's interim mitigations or discontinue use of the plugin on shared hosting servers.
  • Audit shared hosting accounts for unnecessary FTP and web shell access, and remove or restrict it where not required.
  • Verify CloudLinux/CageFS protections are enabled and current, since the flaw abuses symlink handling within that isolation model.
  • Track remediation against CISA BOD 26-04 requirements for internet-exposed assets.

Detection

  • Review cPanel/WHM and LiteSpeed plugin logs for symlink creation or access activity originating from low-privileged hosting accounts.
  • Hunt for file access or writes outside a tenant's home directory that traverse symlinks, especially in shared hosting environments.
  • Monitor for unexpected changes to files owned by other accounts or the host on CloudLinux/CageFS servers.
  • Correlate FTP and web shell session activity with subsequent cross-account file operations on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-54420 to the Known Exploited Vulnerabilities catalog on 15 June 2026 as "LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 18 June 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-54420 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-48172LiteSpeed cPanel Plugin Redis Feature Privilege EscalationThe LiteSpeed User-End cPanel Plugin before 2.4.5 mishandles Redis enable/disable functionality, allowing privilege escalation that may reach root. I…KEVEPSS 1.0%analysed9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed7.1CVE-2025-0111PAN-OS authenticated file read via management web interfacePAN-OS contains an authenticated file read vulnerability that lets a user with network access to the management web interface read files on the PAN-O…KEVEPSS 2.0%analysed7.5CVE-2023-45727Proself XXE flaw allows unauthenticated file readProself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote…KEVEPSS 3.5%analysed9.8CVE-2024-34102Adobe Commerce and Magento XXE flaw allows unauthenticated code executionAdobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML do…KEVEPSS 100%analysed9.1CVE-2022-27593QNAP Photo Station external resource reference allows system file modificationQNAP Photo Station on NAS devices contains an externally controlled reference to a resource flaw (CWE-610) that lets an attacker modify system files.…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2026-54420), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.