Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-54420

Published 2026-06-14
Updated 2 months ago
Vendor/s
LiteSpeed
Product/s
cPanel Plugin
Version/s
* > 2.4.8
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
8.5
/ 10
High
Severity Details
Base score
8.5 High
Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-54420 is a high-severity symlink vulnerability in LiteSpeed cPanel plugins (versions < 2.4.8) actively exploited in the wild.

CPE

LiteSpeed logo
LiteSpeed
Product Version Start Version End (excl.) Status
litespeed_cpanel_plugin * 2.4.8 vulnerable
litespeed_whm_plugin * 5.3.2.0 vulnerable

Related weakness (CWE)

CWE-61

Remediation plan

1

Apply official patches

Update the LiteSpeed WHM Plugin to version 5.3.2.0 or later to receive the necessary security fixes for the integrated cPanel plugin.

2

Update affected systems

Ensure all instances of the LiteSpeed cPanel plugin are updated to version 2.4.8 or higher to address the symlink mishandling flaw.

3

Restrict access

Enforce strict access controls for FTP and web shells. Audit CageFS and CloudLinux configurations to ensure proper isolation between hosting tenants.

4

Monitor for exploitation

Analyze audit logs for the creation of symbolic links targeting sensitive system paths or cross-account directories, which may indicate active exploitation.

Detection Guidance

"Detecting exploitation of CVE-2026-54420 requires monitoring for suspicious symbolic link creation within shared hosting directories. Security teams should audit web server and FTP logs for patterns indicating attempts to access sensitive system files or other users' data via symlinks. Specifically, look for symlinks pointing to /etc/passwd or configuration files outside the user's CageFS environment. Utilize file integrity monitoring (FIM) to alert on unauthorized link modifications in high-risk directories."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management