CVE Tools
Back to feed
Exploited in the wild LiteSpeed cPanel Plugin privilege-escalation LiteSpeed WHM Plugin LiteSpeed web-app

LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

CVE-2026-54420 is a privilege escalation issue in the LiteSpeed cPanel plugin (before version 2.4.8) that is reportedly under active attack, allowing a low-privileged tenant on shared hosting to escape isolation and obtain full root access. The flaw involves improper handling of user-controlled symlinks when the server runs CloudLinux/CageFS, which matters because compromising one account can put all sites on the same host at risk. LiteSpeed has remediated the problem in cPanel plugin v2.4.8 (bundled with WHM Plugin v5.3.2.1), so administrators should patch immediately and investigate logs for suspicious activity.