CVE-2026-54420

Published Jun 14, 2026

Last updated a month ago

Exploit knownCVSS high 8.5
Zero-day
FTP
Server
Port (22)

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-54420 identifies a vulnerability within the LiteSpeed cPanel plugin, affecting versions prior to 2.4.8, which are included in LiteSpeed WHM PlugIn versions before 5.3.2.0. This flaw stems from the plugin's inadequate handling of symbolic links (symlinks). The vulnerability can be leveraged by a user possessing FTP or web shell access on a shared hosting server that utilizes CloudLinux/CageFS. Through the manipulation of symlinks, an attacker could potentially access or execute arbitrary files located outside of their designated directories, a scenario categorized as a path traversal vulnerability (CWE-61). This issue was actively exploited in May 2026.

Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Source
cve@mitre.org
NVD status
Analyzed
Products
litespeed_cpanel_plugin, litespeed_whm_plugin

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.5
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Exploit added on
Jun 15, 2026
Exploit action due
Jun 18, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

cve@mitre.org
CWE-61

Social media

Hype score
Not currently trending
  1. 00:00 UTC: CVE-2026-54420 disclosed. CISA: CVE-2026-54420 added to Known Exploited Vulnerabilities — LiteSpeed cPanel Plugin Status: ✅ Confirmed exploited in the wild Date added: 2026-06-15 Required action: Apply mitigations in accordance with vendor instructions,…

    @lyrie_ai

    10 Jul 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. LiteSpeed-cPanel-Plugin: CVE-2026-54420 landet im CISA-KEV-Katalog CVE-2026-54420 betrifft das LiteSpeed-cPanel-Plugin auf Shared-Hosting-Systemen https://t.co/eKspoQdUGA https://t.co/ZcO3viAdUu

    @schoenfelderED

    17 Jun 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Joomla JCE CVE-2026-48907 and LiteSpeed cPanel CVE-2026-54420 are being actively exploited, enabling file uploads, PHP execution, and possible root escalation on shared hosting servers. #Joomla #LiteSpeed #CISA https://t.co/o3etmdvGBO

    @TweetThreatNews

    17 Jun 2026

    192 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA adds LiteSpeed cPanel privilege escalation flaw CVE-2026-54420 to KEV catalog. Patch to WHM Plugin v5.3.2.1 by June 18, 2026. https://t.co/X5tWEQswXE #LiteSpeed #CVE #PrivilegeEscalation #CloudLinux #CageFS #SharedHosting #KEVcatalog #CISA #Namecheap #ServerSecurity https:

    @redsecuretech

    16 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISAが既知の悪用された脆弱性2件をカタログに追加 CVE-2026-20262 Cisco Catalyst SD-WAN Managerのディレクトリまたはパスのトラバーサル脆弱性 CVE-2026-54420 LiteSpeed cPanelプラグインのUNIXシンボリックリンク(Symlink)の

    @foxbook

    16 Jun 2026

    203 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Oh cPanel servers about to be hacked? Update asap or remove LiteSpeed cPanel Plugin. CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

    @zerotalktoai

    15 Jun 2026

    70 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. The CVE that was published today for LiteSpeed's WHM plugin prior to v2.4.8 refers to the same vulnerability we disclosed (and patched) two weeks ago. CVE-2026-54420: https://t.co/1xR8NH6Yvy

    @litespeedtech

    15 Jun 2026

    99 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🛡️ We added Cisco Catalyst SD-WAN Manager vulnerability CVE-2026-20262 and LiteSpeed cPanel Plugin vulnerability CVE-2026-54420 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyber

    @CISACyber

    15 Jun 2026

    4330 Impressions

    9 Retweets

    28 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  9. ⚠️ CRITICAL: ‼️ CVE-2026-54420: LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn b... CVE-2026-54420 is a critical symlink mishandling vulnerability in LiteSpeed cPanel plugin versions before 2.4.8 and LiteSpeed WHM Plugin versions before 5.3.

    @lenngrenm

    14 Jun 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2026-54420 LiteSpeed cPanel Plugin Symlink Mishandling in CloudLinux/CageFS Environments https://t.co/AaEimojznY

    @VulmonFeeds

    14 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations