Knox CVE Database
/
CVE-2026-54420
High
8.5

CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

Added to the CISA KEV catalog:
June 15, 2026

Overview

The LiteSpeed cPanel plugin contains a symlink-following vulnerability that allows a low-privileged tenant on a shared hosting server to escalate privileges to root. An attacker with FTP or web shell access plants a crafted symbolic link in a location the plugin processes with elevated permissions; when the plugin follows the link without adequate validation, the attacker escapes the CloudLinux/CageFS sandbox and gains full control of the host. All cPanel plugin versions before 2.4.8 are affected, and exploitation was observed in the wild before the patch was released.

Vulnerability details

Affected vendor
LiteSpeed
Affected product
cPanel Plugin
Weakness type (CWE)
CWE-61

CWE-61 describes a class of flaw where a privileged process follows a symbolic link placed by a lower-privileged user, operating on an attacker-chosen file rather than the intended target. In the context of the LiteSpeed cPanel plugin, the plugin runs with root-level permissions on shared hosting servers protected by CloudLinux/CageFS. Because the plugin does not adequately validate symlinks supplied from within a user's filesystem space, an attacker can redirect the plugin's file operations to arbitrary paths outside the CageFS sandbox, bypassing the isolation boundary the hosting environment relies on.


An attacker who holds a low-privileged account on the shared server, reachable via FTP or a web shell, plants a crafted symlink and then triggers the vulnerable code path by chaining two specific cPanel API calls: a call to generateEcCert immediately followed by packageUserSize for the same user. Legitimate UI flows do not chain these calls, and the exploit pattern involves 7 to 10 concurrent requests per attempt rather than the single sequential call a normal user session produces. Successful exploitation yields full root access to the host, escaping CageFS and giving the attacker complete control over confidentiality, integrity, and availability of the server.

Severity and impact

8.5
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Search cPanel and system logs for the exploit chain using the vendor-supplied command: grep for cpanel_jsonapi_func=generateEcCert or packageUserSize paired with cert_action_entry geneccert in /usr/local/cpanel/logs/ and /var/cpanel/logs/. Any output warrants investigation.
  • Confirm exploitation by looking for generateEcCert immediately followed by packageUserSize for the same user account, sourced from the same IP, with 7 to 10 concurrent requests per attempt. A single sequential call from the UI is normal; this concurrency pattern is not.
  • Audit actions taken by any source IP identified in the above log review, checking system logs for post-escalation activity such as new user creation, cron modifications, or outbound connections initiated under root context.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 18, 2026

Additional hardening

  • Upgrade the LiteSpeed cPanel plugin to version 2.4.8 and the LiteSpeed WHM Plugin to version 5.3.2.1 or later. The vendor advisory confirms 5.3.2.1 is the release that bundles the fix; the WHM plugin update also updates the user-end plugin.
  • If an immediate upgrade is not possible, remove the user-end cPanel plugin using the vendor-provided uninstall command to eliminate the vulnerable attack surface until patching can be completed.
  • Restrict FTP and web shell access to the minimum set of accounts that require it, and enforce per-account CageFS policies to reduce the filesystem locations an attacker can use to plant symlinks.
  • After patching, run the vendor-supplied grep command against cPanel and system logs to determine whether exploitation occurred before the update, and follow the vendor's forensic triage guidance for any affected source IPs.

Key dates

Published (NVD)
June 14, 2026
Added to CISA KEV
June 15, 2026
Remediation deadline
June 18, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-54420 affect my FedRAMP authorization?

If LiteSpeed cPanel Plugin runs inside your authorization boundary, CVE-2026-54420 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its June 18, 2026 remediation deadline has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. Remediate it now or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-54420?

Knox does not patch LiteSpeed cPanel Plugin on your behalf. Under the FedRAMP shared-responsibility model, that remediation belongs to you. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that work, plus Knox's automated continuous monitoring platform and the audit-artifact coverage your next assessment will require. Applying the fix is your responsibility. Managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-54420. Exposure surfaces during ongoing monitoring rather than only when an assessor reviews your posture at a scheduled assessment. That difference gives you time to act before a finding becomes a formal conversation with your agency.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-54420's remediation deadline of June 18, 2026 has passed. What happens now?

If CVE-2026-54420 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship clean.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting