← Back to CVE List
CVE-2026-54420NVD
Vulnerability Summary
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
CVSS v3.1 Base Metrics — Score 8.5 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Litespeedtech Litespeed Cpanel Plugin < 2.4.8
- Litespeedtech Litespeed Whm Plugin < 5.3.2.0
- Litespeedtech Litespeed Cpanel Plugin 2.4.8
- Litespeedtech Litespeed Whm Plugin 5.3.2.0