The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply fixes by June 18, 2026.
The vulnerability, tracked as CVE-2026-54420 (CVSS score: 8.5), is a privilege escalation issue that allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS. According to CVE.org, the LiteSpeed cPanel plugin before version 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by such users.
It is currently unknown how the vulnerability is being exploited in the wild or if any attacks have been successful. LiteSpeed has urged users to run a specific grep command to check if their servers are affected. If the command shows no output, the server is not impacted. If there is output, LiteSpeed has shared additional indicators to rule out false positives, such as generateEcCert immediately followed by packageUserSize for the same user, and 7-10 concurrent calls per attempt.
Namecheap has been credited with bringing the issue to LiteSpeed’s attention on May 31, 2026. Users are advised to upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled with cPanel plugin v2.4.8) or higher to patch the vulnerability.
CVEs: CVE-2026-54420, CVE-2026-11645
Companies: LiteSpeed, CloudLinux, cPanel, Namecheap, CISA
Products: LiteSpeed cPanel Plugin, LiteSpeed WHM Plugin, CloudLinux, CageFS
Original source: thehackernews.com