8.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
AI Analysis
LiteSpeed cPanel plugin mishandles symlinks, allowing for potential exploits on shared hosting servers.
Basic Information
ID
CVE-2026-54420
Source
mitre
Published
Jun 14, 2026 at 03:23
Affected Product
Vendor
LiteSpeed Technologies
Product
cPanel Plugin
Version
2.3
Affected Versions
LiteSpeed Technologies cPanel Plugin 2.3
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
LiteSpeed Technologies
Product
cPanel Plugin
Version
2.3