CVE-2026-54420 CRITICAL

LiteSpeed cPanel Plugin Vulnerability
Generated: 10 Oct 2026 19:57 • CVE Threat Intelligence

Description

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

9.8
CVSS CRITICAL

Details

Published
15 Jun 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
LiteSpeed
Product
cPanel Plugin
Fix Version
Vendor Patch / Mitigation Available