LiteSpeed cPanel Plugin Vulnerability
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
CVSS Score
9.8
CRITICAL
Published
15 Jun 2026 00:00
Modified
N/A
Vendor
LiteSpeed
Product
cPanel Plugin
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-61
Affected Systems
LiteSpeed
cPanel Plugin
LiteSpeed
CPanel Plugin
External Links
KEV Status
Known Exploited Vulnerability