
[CIVN-2026-0323] Privilege Escalation Vulnerability in LiteSpeed cPanel Plugin
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Privilege Escalation Vulnerability in LiteSpeed cPanel Plugin
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
LiteSpeed cPanel Plugin versions prior to 2.4.8.
Overview
A vulnerability has been reported in LiteSpeed cPanel Plugin which could allow an attacker to gain elevated privileges on the targeted system.
Target Audience:
Web hosting providers, server administrators, and cPanel users managing LiteSpeed-powered shared hosting environments.
Risk Assessment:
High risk of privilege escalation, full server compromise.
Impact Assessment:
Potential for root-level access, server compromise, disruption of hosted services.
Description
LiteSpeed User-End cPanel Plugin is a management plugin that allows users to manage LiteSpeed Web Server features directly through the cPanel interface.
A vulnerability exists in the LiteSpeed cPanel Plugin due to improper handling of user-supplied symlinks links. An attacker with FTP access or web shell access on a shared hosting server running CloudLinux/CageFS could exploit this vulnerability to bypass intended security restrictions.
Successful exploitation of this vulnerability could allow an attacker to gain elevated privileges on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/
Vendor Information
LiteSpeed
https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/
References
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/
CVE Name
CVE-2026-54420
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo5SiQACgkQ3jCgcSdc
ys9yjg/+JJOqia/2mzuXDOvvS9vYWoRs7MbeLIcsIrILDXQtfNbB2jIgY1Hx+hai
USQU129DV5sjM2daNH2CfISTL+c5CMMh84b3Vne0ZtrfJv9k1m6J3cm9oL3gz3KL
RBpnf539jzs3gI0vfAmjHXuZr/NCn+bpUA3ZZC2+w0hypKeKqyPA1FzGZFXRCHCh
f92/W1GSCmBF4kWAJ1sfkjooUQ6FNtaMJ7HxSCJYiu/EHX/SSZuIJfa3hGJpK6cw
rFmI51quPdQx047j9KYfvphMPHs3Vu0gKpPjZmFqzvqv24nQuhJVtP0FKwkSaTzf
dyS3gc71pzPcVosG5EuBj4cAy+n7LF6oiOJmZqgss9sKvsQt0n5PXRKjDnljQxgt
9LlPkmVwkFHBpdFACqLJRmetIZUxw3Bb3ysePDPgPYPKuERfXqqkm8ePaNwThdvP
JqcX/jNDPOgm2y4LD2FxPVeAcoCa3s2G2rgxUOHdpG4opd6ogcxjxywKGGkSWpE3
HRysg9nRFCVvX/nl3bODItCvyoB91QFL4PU5U2/8j+vfCIijfx1rwLrHlEiqTgpi
b5wU4mbNeAQ7q4/nRjHd0UXpkXetQdvnuL2tuyxFOO5LwareOInypJUEMnGQVBgj
OKQjYjna5BD5prF5j7/Kl3Cygz9KBtut3H43Uwcc9ZUKRb3EzNQ=
=k4ep
—–END PGP SIGNATURE—–


