CVE-2026-54420: LiteSpeed cPanel Plugin Symlink Escape on Shared Hosting
ID: 3af94c11-752b-5523-821a-6a8759d23390
STIX ID: report--3af94c11-752b-5523-821a-6a8759d23390
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-54420:** A high-severity symlink mishandling vulnerability in LiteSpeed cPanel (<2.4.8) and WHM (<5.3.2.0) plugins permits attackers with FTP or web shell access to escape CloudLinux CageFS isolation, enabling horizontal privilege escalation, credential theft, and cross-account data access; exploitation was confirmed in the wild since May 2026 — hosts must update to 2.4.8/5.3.2.0+ immediately and audit for malicious symlinks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
