---
schema: 1
kind: vulnerability
title: "CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited in the wild (CISA KEV)"
headline: "CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited in the wild (CISA KEV)"
summary: "LiteSpeed cPanel/WHM plugin CVE-2026-54420 in CISA KEV — symlink-following on CloudLinux/CageFS shared hosting, exploited in the wild since May (LiteSpeed, 2026-06-01); added to CISA KEV on 2026-06-15 (CISA, 2026-06-15). Patch to WHM PlugIn 5.3.2.1."
discovered_at: "2026-06-16T05:08:58Z"
event_date: 2026-06-15
run_id: 2026-06-16-38d638e1
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - priv-esc
  - cisa-kev
regions:
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-54420
    cvss: "8.5"
    epss: null
    type: priv-esc
    vector: local
    auth: post-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/"
    publisher: LiteSpeed security update
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog"
    publisher: CISA KEV alert
    role: corroborating
closed_sources: []
evidence:
  - quote: "The LiteSpeed cPanel plugin before 2.4.8 (fixed in the LiteSpeed WHM PlugIn version 5.3.2.1) mishandles symlinks supplied by a user with FTP or web-shell access on a CloudLinux/CageFS shared-hosting server, enabling cross-account file access and privilege escalation; NVD records exploitation in the …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch the LiteSpeed cPanel/WHM plugin (CVE-2026-54420)** to WHM PlugIn version 5.3.2.1 / plugin 2.4.8 — exploited in the wild on shared CloudLinux/CageFS hosting since May. Prioritise any public-sector tenant on shared hosting."
migrated_from: briefs/2026-06-16.md
---

The **LiteSpeed cPanel plugin before 2.4.8** (fixed in the LiteSpeed WHM PlugIn version 5.3.2.1) mishandles symlinks supplied by a user with FTP or web-shell access on a CloudLinux/CageFS shared-hosting server, enabling cross-account file access and privilege escalation; NVD records exploitation in the wild in May 2026 ([NVD CVSS 8.5](https://nvd.nist.gov/vuln/detail/CVE-2026-54420)). CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-15 ([CISA, 2026-06-15](https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog)). The exposure is most acute for hosting providers and any public-sector tenant on shared CloudLinux infrastructure. Patch to WHM PlugIn 5.3.2.1 / cPanel plugin 2.4.8.
