LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to the LiteSpeed WHM PlugIn v5.3.2.0 or higher (which includes the cPanel PlugIn v2.4.8).
Workaround
Disable the cPanel PlugIn for LiteSpeed
References
History
Sun, 14 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Manipulation Allowing Remote Code Execution in LiteSpeed cPanel Plugin |
Sun, 14 Jun 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-14T03:23:12.863Z
Reserved: 2026-06-14T03:23:12.439Z
Link: CVE-2026-54420
No data.
Status : Received
Published: 2026-06-14T04:16:28.630
Modified: 2026-06-14T04:16:28.630
Link: CVE-2026-54420
No data.
OpenCVE Enrichment
Updated: 2026-06-14T05:30:07Z
Weaknesses