LiteSpeed Technologies' cPanel Plugin has a privilege-escalation flaw under active exploitation, and CISA added it to its Known Exploited Vulnerabilities catalog with a remediation deadline of June 18 for federal civilian agencies, per the CISA KEV catalog.
The vulnerability, tracked as CVE-2026-54420, stems from improper symlink handling in the LiteSpeed cPanel user-end plugin. LiteSpeed published a security advisory rating the flaw at CVSS 8.5 and noting it was reported by Namecheap. An attacker who has already obtained FTP access or a web shell on a shared hosting server running CloudLinux or CageFS can follow symlinks to escalate their privileges all the way to root. The fix ships in LiteSpeed WHM Plugin v5.3.2.1 bundled with cPanel plugin v2.4.8.
The attack surface is narrow but serious for shared hosting environments. An attacker needs an existing foothold (FTP credentials or a deployed web shell) before exploiting the symlink flaw. Once in, a full root compromise of the host is possible. LiteSpeed recommends hosting administrators run the following grep check against server logs to identify any prior exploitation attempts:
grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/nullIf the command returns output, LiteSpeed advises checking for two indicators that distinguish real exploitation from legitimate traffic: the generateEcCert function immediately followed by packageUserSize for the same user (legitimate UI flows do not chain these two calls), and 7 to 10 concurrent requests per attempt (genuine UI interactions issue one call at a time). Hosting providers running CloudLinux or CageFS should run this check before patching to determine whether the server was hit before the fix was applied.
Private-sector operators on LiteSpeed-powered cPanel hosts carry no mandatory federal deadline, but a root-privilege path on shared infrastructure warrants the same urgency. Upgrading to WHM Plugin v5.3.2.1 or later closes the vulnerability.












