Skip to content

CISA Adds LiteSpeed cPanel Plugin Privilege-Escalation Flaw to Known Exploited Vulnerabilities Catalog

CISA added a privilege-escalation flaw in LiteSpeed cPanel Plugin (CVE-2026-54420, CVSS 8.5) to its KEV catalog. Federal agencies must patch by June 18; the fix ships in WHM Plugin v5.3.2.1.

LiteSpeed Security Update banner for the cPanel user-end plugin
Credit: LiteSpeed

LiteSpeed Technologies' cPanel Plugin has a privilege-escalation flaw under active exploitation, and CISA added it to its Known Exploited Vulnerabilities catalog with a remediation deadline of June 18 for federal civilian agencies, per the CISA KEV catalog.

The vulnerability, tracked as CVE-2026-54420, stems from improper symlink handling in the LiteSpeed cPanel user-end plugin. LiteSpeed published a security advisory rating the flaw at CVSS 8.5 and noting it was reported by Namecheap. An attacker who has already obtained FTP access or a web shell on a shared hosting server running CloudLinux or CageFS can follow symlinks to escalate their privileges all the way to root. The fix ships in LiteSpeed WHM Plugin v5.3.2.1 bundled with cPanel plugin v2.4.8.

The attack surface is narrow but serious for shared hosting environments. An attacker needs an existing foothold (FTP credentials or a deployed web shell) before exploiting the symlink flaw. Once in, a full root compromise of the host is possible. LiteSpeed recommends hosting administrators run the following grep check against server logs to identify any prior exploitation attempts:

grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null

If the command returns output, LiteSpeed advises checking for two indicators that distinguish real exploitation from legitimate traffic: the generateEcCert function immediately followed by packageUserSize for the same user (legitimate UI flows do not chain these two calls), and 7 to 10 concurrent requests per attempt (genuine UI interactions issue one call at a time). Hosting providers running CloudLinux or CageFS should run this check before patching to determine whether the server was hit before the fix was applied.

Private-sector operators on LiteSpeed-powered cPanel hosts carry no mandatory federal deadline, but a root-privilege path on shared infrastructure warrants the same urgency. Upgrading to WHM Plugin v5.3.2.1 or later closes the vulnerability.

Share this story

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.