LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

Project Subscriptions

Vendors Products
Litespeed Technologies Subscribe
Cpanel Plugin Subscribe
Litespeedtech Subscribe
Litespeed Cpanel Plugin Subscribe
Litespeed Whm Plugin Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to the LiteSpeed WHM PlugIn v5.3.2.0 or higher (which includes the cPanel PlugIn v2.4.8).


Workaround

Disable the cPanel PlugIn for LiteSpeed

History

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Symbolic Link Path Traversal in LiteSpeed cPanel Plugin Allows Remote Code Execution

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Symlink Manipulation Allowing Remote Code Execution in LiteSpeed cPanel Plugin

Mon, 15 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Litespeedtech
Litespeedtech litespeed Cpanel Plugin
Litespeedtech litespeed Whm Plugin
CPEs cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:*
Vendors & Products Litespeedtech
Litespeedtech litespeed Cpanel Plugin
Litespeedtech litespeed Whm Plugin

Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-06-15T00:00:00+00:00', 'dueDate': '2026-06-18T00:00:00+00:00'}


Mon, 15 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 14 Jun 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Litespeed Technologies
Litespeed Technologies cpanel Plugin
Vendors & Products Litespeed Technologies
Litespeed Technologies cpanel Plugin

Sun, 14 Jun 2026 05:30:00 +0000

Type Values Removed Values Added
Title Symlink Manipulation Allowing Remote Code Execution in LiteSpeed cPanel Plugin

Sun, 14 Jun 2026 04:00:00 +0000

Type Values Removed Values Added
Description LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-16T03:56:05.377Z

Reserved: 2026-06-14T03:23:12.439Z

Link: CVE-2026-54420

cve-icon Vulnrichment

Updated: 2026-06-15T17:14:45.605Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-14T04:16:28.630

Modified: 2026-06-16T12:55:03.590

Link: CVE-2026-54420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T07:30:05Z

Weaknesses