HomeSecurityCISA: Vulnerability in LiteSpeed ​​cPanel Plugin Allows Privilege Escalation

CISA: Vulnerability in LiteSpeed ​​cPanel Plugin Allows Privilege Escalation

CISA has added a critical vulnerability ( CVE -2026-54420 ) in the LiteSpeed ​​cPanel Plugin to its Known Exploited Vulnerabilities (KEV) list . The vulnerability, with a CVSS score of 8.5 , allows a user with FTP or web shell access to escalate to root privileges on shared hosting servers running CloudLinux or CageFS. Active exploitation of the vulnerability has been confirmed since May 2026, putting thousands of hosting environments worldwide at risk.

LiteSpeed ​​cPanel Plugin

According to the CVE.org, LiteSpeed ​​cPanel Plugin versions prior to 2.4.8 (as distributed via LiteSpeed ​​WHM PlugIn prior to 5.3.2.0) do not properly handle symbolic links (symlinks) created by users with low privileges. This is a CWE-61 (UNIX Symbolic Link Following), which is particularly dangerous in CloudLinux and CageFS environments, where tenant isolation is a fundamental security principle. A malicious user exploiting CVE-2026-54420 could “break” this isolation and gain complete control of the server.

See also: CISA: LiteSpeed ​​cPanel Plugin Vulnerability in KEV Catalog

Namecheap is credited with having disclosed the issue on May 31, 2026. CISA requires Federal Civilian Executive Branch (FCEB) agencies to implement the fixes by June 18, 2026 , which underscores the urgency of the threat. Inclusion on the KEV list is a strong signal that the exploit is verified and not just theoretical.

CVE-2026-54420: Technical details and exploitation method

CVE -2026-54420 exploits the way the LiteSpeed ​​cPanel Plugin handles symlinks provided by users with FTP or web shell. In a typical shared hosting environment, multiple customers share the same physical server, with CloudLinux/CageFS providing isolation between them. The vulnerability allows a tenant to create malicious symlinks that, when processed by the plugin with elevated privileges, lead to privilege escalation to root. This means that a simple hosting user can gain complete control of the entire server.

LiteSpeed a potential exploit. Specifically, administrators are asked to run a grep on the system logs:

grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null

If the command does not return any results, the server is not affected. In case output is displayed, LiteSpeed ​​has provided additional indicators to rule out false positives: the appearance of the generateEcCert immediately after packageUserSize for the same user (legitimate UI flows do not combine these commands), as well as 7-10 simultaneous calls per attempt (legitimate UI runs one at a time). These patterns are clear indications of malicious activity.

Technically, the vulnerability falls into a broader category of infrastructure weaknesses that attackers exploit to turn a limited initial access into a full system compromise. The fact that only FTP or web shell — something that is relatively easy to obtain through phishing, stolen credentials, or exploiting other application vulnerabilities — makes CVE-2026-54420 particularly attractive to malicious actors targeting hosting providers.

See also: LiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

CISA: Vulnerability in LiteSpeed ​​cPanel Plugin Allows Privilege Escalation

Protection from CVE-2026-54420: Immediate actions

An immediate upgrade to LiteSpeed ​​WHM Plugin v5.3.2.1 (which includes the cPanel plugin v2.4.8 ) or later is the primary recommendation for all administrators using affected systems. If an immediate upgrade is not possible, LiteSpeed ​​recommends removing the user-end plugin as a temporary measure to reduce the attack surface. Administrators should also review cPanel and hosting logs for suspicious activity related to symlinks .

A critical point to emphasize: if a server was exposed while running a vulnerable version, simply applying the security update may not be enough. A root-level exploit may have left behind backdoors, modified system files, or other permanent changes. For this reason, experts recommend a full compromise assessment ofeachserver that was exposed, and not just applying the patch. Hosting providers serving customers in Greece and Europe should immediately inform their users of a potential exposure, especially in light of GDPR obligations.

See also: WordPress: New serious vulnerability in LiteSpeed ​​Cache plugin

As The Hacker News, CISA has already activated emergency response procedures for federal agencies. CVE-2026-54420 is a reminder that vulnerabilities in plugins and hosting management tools can have devastating consequences, as a single compromised server can affect dozens or hundreds of websites and businesses at once. Timely updates and constant monitoring of systems remain the most effective defenses against such threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS