CVE-2026-54420
HIGH KEVLitespeed Technologies cPanel Plugin < 2.4.8 - UNIX Symbolic Link (Symlink) Following
Title source: ruleExploitation Summary
CVE-2026-54420 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 15, 2026. EIP tracks 4 public exploits from researchers including fevar54, mahfuzreham, Resellnom.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-54420, a symlink following vulnerability in LiteSpeed cPanel Plugin and WHM Plugin. The exploit demonstrates privilege escalation by creating malicious symlinks via FTP to read sensitive files outside the user's designated directory.
Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Exploits (4)
This repository contains a functional Python exploit for CVE-2026-54420, a symlink following vulnerability in LiteSpeed cPanel Plugin and WHM Plugin. The exploit demonstrates privilege escalation by creating malicious symlinks via FTP to read sensitive files outside the user's designated directory.
This repository provides defensive mitigation and detection scripts for CVE-2026-54420, a symlink-related vulnerability in the LiteSpeed cPanel Plugin. It includes tools for auditing symlinks, updating LiteSpeed, and hunting for indicators of compromise (IOCs) in shared hosting environments.
This repository provides defensive scripts for detecting and mitigating CVE-2026-54420, a symlink-related vulnerability in LiteSpeed cPanel Plugin. It includes tools for auditing symlinks, updating LiteSpeed, and hunting for indicators of compromise (IOCs).
This repository contains a functional exploit PoC for CVE-2026-54420, demonstrating unauthenticated remote code execution via template injection in a hypothetical web application's '/api/render' endpoint. The script includes multiple payload variations for different template engines (Jinja2, Freemarker, Velocity, Smarty, Twig) and supports command execution, enumeration, and reverse shell capabilities.
References (3)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H