Skip to content
Security Update For Litespeed Cpanel Plugin 2

Security Update For Litespeed Cpanel Plugin 2

blog.litespeedtech.com June 16, 2026

We have another urgent security update for LiteSpeed’s user-end plugin for cPanel.

Last night we were made aware of a vulnerability affecting our user-end cPanel plugin (LiteSpeed’s WHM plugin was not affected). We patched this vulnerability in v2.4.8.

Please update to the latest version of the cPanel user-end plugin, which is bundled with the WHM plugin..

This Privilege Escalation vulnerability, which was reported to us by the team at Namecheap, has been assigned CVE-2026-54420 .

A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS.

This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.

Use the following command to determine if your server has been affected:

If there is no output, then your server has not been affected.

If this command results in any output, the vulnerability may have been exploited on your server. There can be false positives, so look for the following to confirm:

To determine any damage done, examine the system logs for any actions taken by the detected IPs. If you need assistance, you may our support team .

We urgently recommend that those using the LiteSpeed user-end plugin for cPanel upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled w/ cPanel plugin v2.4.8) or higher to patch this vulnerability.

To update the WHM plugin, run this command, which will also update the user-end plugin, if you currently have it installed:

If you cannot upgrade at this time, you can use the following command to remove the user-end plugin and avoid this vulnerability:

Once you’ve updated the WHM plugin, you can run the following commands, which will reinstall the user-end plugin and turn on autoinstall:

We thank Namecheap for bringing the original issue to our attention. We’d also like to thank the cPanel team for their immediate action in preventing further exploitation on additional servers. The vulnerability has been patched, so if you are keeping your cPanel plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so immediately.