CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Other sources
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LiteSpeed WHM PlugInto a version that resolves this vulnerability.Fixed in 5.3.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54420?
The severity of CVE-2026-54420 is rated as high with a score of 8.5.
How do I fix CVE-2026-54420?
To fix CVE-2026-54420, upgrade to the LiteSpeed WHM Plugin version 5.3.2.0 or higher.
What software is affected by CVE-2026-54420?
The affected software includes the LiteSpeed LiteSpeed cPanel Plugin and LiteSpeed WHM Plugin.
Can CVE-2026-54420 be exploited remotely?
Yes, CVE-2026-54420 can be exploited remotely due to its nature of mishandling symlinks on shared hosting servers.
Is there a known exploitation of CVE-2026-54420?
Yes, CVE-2026-54420 was exploited in the wild starting May 2026.