LiteSpeed Technologies Vulnerabilities and Affected Products
Vulnerabilities associated with cPanel Plugin.
Products
Clear product- LiteSpeed Cache12 vulnerabilities
- OpenLiteSpeed4 vulnerabilities
- LiteSpeed Web Server3 vulnerabilities
- OpenLiteSpeed Web Server3 vulnerabilities
- cPanel Plugin2 vulnerabilities
- LSWS Enterprise1 vulnerability
- WHM Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-54420HIGH | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following VulnerabilityLiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. CWE-61Jun 14, 2026 | CVSS8.5v3.1 | EPSS1.44% | PoCs4 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-48172CRITICAL | LiteSpeed cPanel Plugin Privilege Escalation VulnerabilityLiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block t… CWE-266May 21, 2026 | CVSS10.0v4.0 | EPSS18.9% | PoCs4 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |