Skip to content
CISA warns of LiteSpeed cPanel plugin flaw allowing root access

CISA warns of LiteSpeed cPanel plugin flaw allowing root access

Feeds.4Sysops IT News June 16, 2026

A critical privilege escalation vulnerability in the LiteSpeed cPanel plugin is now being exploited in the wild, prompting a warning from CISA. The flaw, tracked as CVE-2026-54420, allows attackers with basic FTP or web shell access to gain full root privileges on shared hosting environments. This security hole specifically affects servers running CloudLinux or CageFS due to the improper handling of user-provided symlinks. Source

Extracted Entities