Skip to content
COOEY

EXPOSURES › CVE-2026-54420

CVE-2026-54420

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-06-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-54420 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildsupply-chainunpatched

LiteSpeed cPanel plugin allows attackers to traverse symlink chains to escape shared hosting isolation on CloudLinux/CageFS.

This symlink following vulnerability in the LiteSpeed cPanel plugin enables attackers with FTP or web shell access to bypass shared hosting isolation on CloudLinux/CageFS environments. DIB organizations using LiteSpeed cPanel plugins face elevated risk of lateral movement and data exfiltration from compromised shared servers, requiring immediate patching and isolation verification.

Shame score — A known symlink traversal vulnerability in a widely-used cPanel plugin that allows isolation bypass on shared hosting platforms.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.