CVE-2026-54420

HIGH KEV

Litespeed Technologies cPanel Plugin < 2.4.8 - UNIX Symbolic Link (Symlink) Following

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2026-54420 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 15, 2026. EIP tracks 4 public exploits from researchers including fevar54, mahfuzreham, Resellnom.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-54420, a symlink following vulnerability in LiteSpeed cPanel Plugin and WHM Plugin. The exploit demonstrates privilege escalation by creating malicious symlinks via FTP to read sensitive files outside the user's designated directory.

Description

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

Exploits (4)

github WORKING POC
by fevar54 · pythonpoc
https://github.com/fevar54/CVE-2026-54420-LiteSpeed-Symlink-Exploit

This repository contains a functional Python exploit for CVE-2026-54420, a symlink following vulnerability in LiteSpeed cPanel Plugin and WHM Plugin. The exploit demonstrates privilege escalation by creating malicious symlinks via FTP to read sensitive files outside the user's designated directory.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: LiteSpeed cPanel Plugin < 2.4.8, LiteSpeed WHM Plugin < 5.3.2.0
Auth required
Prerequisites: FTP or web shell access on a shared hosting server running CloudLinux/CageFS
mistral-large-3 · analyzed Jun 18, 2026 Full analysis →
github SCANNER
by mahfuzreham · shellpoc
https://github.com/mahfuzreham/litespeed-cpanel-cve-2026-54420-fix

This repository provides defensive mitigation and detection scripts for CVE-2026-54420, a symlink-related vulnerability in the LiteSpeed cPanel Plugin. It includes tools for auditing symlinks, updating LiteSpeed, and hunting for indicators of compromise (IOCs) in shared hosting environments.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: LiteSpeed cPanel Plugin < 2.4.8, LiteSpeed WHM Plugin < 5.3.2.0
Auth required
Prerequisites: access to the server · root or administrative privileges
mistral-large-3 · analyzed Jun 16, 2026 Full analysis →
github SCANNER
by Resellnom · shellpoc
https://github.com/Resellnom/litespeed-cpanel-cve-2026-54420-fix

This repository provides defensive scripts for detecting and mitigating CVE-2026-54420, a symlink-related vulnerability in LiteSpeed cPanel Plugin. It includes tools for auditing symlinks, updating LiteSpeed, and hunting for indicators of compromise (IOCs).

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: LiteSpeed cPanel Plugin < 2.4.8, LiteSpeed WHM Plugin < 5.3.2.0
Auth required
Prerequisites: access to the affected system · administrative privileges
mistral-large-3 · analyzed Jun 16, 2026 Full analysis →
nomisec WORKING POC
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-54420

This repository contains a functional exploit PoC for CVE-2026-54420, demonstrating unauthenticated remote code execution via template injection in a hypothetical web application's '/api/render' endpoint. The script includes multiple payload variations for different template engines (Jinja2, Freemarker, Velocity, Smarty, Twig) and supports command execution, enumeration, and reverse shell capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Hypothetical web application with template injection vulnerability
No auth needed
Prerequisites: Access to the target's '/api/render' endpoint · Python environment with required dependencies
mistral-large-3 · analyzed Jun 16, 2026 Full analysis →

Scores

CVSS v3 8.5
EPSS 0.0126
EPSS Percentile 66.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-06-15
VulnCheck KEV 2026-06-01
ENISA EUVD EUVD-2026-36657
CWE
CWE-61
Status published
Products (3)
LiteSpeed Technologies/cPanel Plugin 2.3 - 2.4.8
litespeedtech/litespeed_cpanel_plugin < 2.4.8
litespeedtech/litespeed_whm_plugin < 5.3.2.0
Published Jun 14, 2026
KEV Added Jun 15, 2026
Tracked Since Jun 14, 2026