Vulnerability record · CVE-2026-54420 · published 14 June 2026
CVE-2026-54420: LiteSpeed cPanel plugin symlink following on shared hosting
Litespeedtech · Litespeed Cpanel Plugin
The LiteSpeed cPanel plugin before 2.4.8 (and LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks supplied by a user who has FTP or web shell access on a shared hosting server running CloudLinux/CageFS. Because the flaw crosses a security boundary on shared infrastructure, a low-privileged tenant can affect files outside their own account. It was exploited in the wild in May 2026 and added to CISA KEV.
Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV with a near-term remediation deadline, despite a modest CVSS base score of 8.5 and low EPSS.
What it is
The LiteSpeed cPanel plugin before 2.4.8 (and LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks supplied by a user who has FTP or web shell access on a shared hosting server running CloudLinux/CageFS. Because the flaw crosses a security boundary on shared infrastructure, a low-privileged tenant can affect files outside their own account. It was exploited in the wild in May 2026 and added to CISA KEV.
Impact
An attacker with FTP or web shell access can follow attacker-controlled symlinks to read or write files outside their hosting account, gaining high confidentiality, integrity and availability impact on other tenants or the host. The scope change in the CVSS vector reflects that the compromise can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the cPanel/WHM plugin interface, but it requires the attacker to already hold a low-privileged account with FTP or web shell access on the shared server. No user interaction is needed; the vector is AV:N/AC:H/PR:L/UI:N/S:C.
Exploitation
Listed in CISA KEV with a due date of 2026-06-18 and described as exploited in the wild in May 2026, so active exploitation is confirmed. EPSS is low at 0.01439 (71.8th percentile), which understates the risk given the KEV entry.
What to do
- Update the LiteSpeed cPanel plugin to 2.4.8 or later and the LiteSpeed WHM PlugIn to 5.3.2.0 or later, per the vendor advisory.
- If patching cannot be completed by the CISA due date, apply the vendor's interim mitigations or discontinue use of the plugin on shared hosting servers.
- Audit shared hosting accounts for unnecessary FTP and web shell access, and remove or restrict it where not required.
- Verify CloudLinux/CageFS protections are enabled and current, since the flaw abuses symlink handling within that isolation model.
- Track remediation against CISA BOD 26-04 requirements for internet-exposed assets.
Detection
- Review cPanel/WHM and LiteSpeed plugin logs for symlink creation or access activity originating from low-privileged hosting accounts.
- Hunt for file access or writes outside a tenant's home directory that traverse symlinks, especially in shared hosting environments.
- Monitor for unexpected changes to files owned by other accounts or the host on CloudLinux/CageFS servers.
- Correlate FTP and web shell session activity with subsequent cross-account file operations on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-54420 to the Known Exploited Vulnerabilities catalog on 15 June 2026 as "LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 18 June 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-54420 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-54420), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.