Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
In plain language
AI Act nowCVE-2026-54420 is a serious symlink-handling flaw in the LiteSpeed cPanel plugin that is already being exploited on shared hosting servers—if you run it on CloudLinux/CageFS, you should update to the fixed versions immediately.
CVE-2026-54420 is a privilege escalation risk caused by symlink mishandling in the LiteSpeed cPanel plugin (before 2.4.8 as packaged in the LiteSpeed WHM PlugIn before 5.3.2.0); attackers with FTP or web shell access can leverage it to escalate privileges on shared hosting (CloudLinux/CageFS).
What to do now
- Check whether you are running the LiteSpeed cPanel plugin (or the LiteSpeed WHM PlugIn bundle) on your shared hosting server with CloudLinux/CageFS.
- Verify your installed versions: LiteSpeed cPanel plugin must be 2.4.8 or later, or LiteSpeed WHM PlugIn must be 5.3.2.0 or later.
- Upgrade to the fixed release: LiteSpeed WHM PlugIn v5.3.2.0+ (includes cPanel PlugIn v2.4.8).
- If you cannot upgrade right away, disable the cPanel PlugIn for LiteSpeed as a temporary mitigation.
- Follow CISA’s triage/forensics guidance and ensure patching is completed by the CISA remediation due date (2026-06-18).
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
References
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and Moreen·The Hacker News· Roundup Fortinet FortiGate Icarus
- 2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)en-us·Daily CyberSecurity (securityonline.info)· Exploited Splunk Enterprise zero-day
- Joomla, LiteSpeed Vulnerabilities Exploited in Attacksen-us·SecurityWeek· Exploited Joomla Content Editor (JCE) Pro rce
- CISA warns of another cPanel plugin flaw exploited in attacksen-us·BleepingComputer· Exploited LiteSpeed cPanel user-end plugin privilege-escalation
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalationen·The Hacker News· Exploited LiteSpeed cPanel Plugin privilege-escalation
- LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)en-us·Daily CyberSecurity (securityonline.info)· Exploited LiteSpeed cPanel Plugin privilege-escalation
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-54420 and every CVE in our database. Create a free account — no credit card required.
Create Free Account