Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to the LiteSpeed WHM PlugIn v5.3.2.0 or higher (which includes the cPanel PlugIn v2.4.8).
Vendor Workaround
Disable the cPanel PlugIn for LiteSpeed
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symbolic Link Path Traversal in LiteSpeed cPanel Plugin Allows Remote Code Execution |
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Manipulation Allowing Remote Code Execution in LiteSpeed cPanel Plugin |
Mon, 15 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litespeedtech
Litespeedtech litespeed Cpanel Plugin Litespeedtech litespeed Whm Plugin |
|
| CPEs | cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:* cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Litespeedtech
Litespeedtech litespeed Cpanel Plugin Litespeedtech litespeed Whm Plugin |
Mon, 15 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Mon, 15 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Mon, 15 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Jun 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litespeed Technologies
Litespeed Technologies cpanel Plugin |
|
| Vendors & Products |
Litespeed Technologies
Litespeed Technologies cpanel Plugin |
Sun, 14 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Manipulation Allowing Remote Code Execution in LiteSpeed cPanel Plugin |
Sun, 14 Jun 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-16T03:56:05.377Z
Reserved: 2026-06-14T03:23:12.439Z
Link: CVE-2026-54420
Updated: 2026-06-15T17:14:45.605Z
Status : Analyzed
Published: 2026-06-14T04:16:28.630
Modified: 2026-06-16T12:55:03.590
Link: CVE-2026-54420
No data.
OpenCVE Enrichment
Updated: 2026-06-18T07:30:05Z