# CVE-2026-54420

## Summary

- **CVE ID:** CVE-2026-54420
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-61
- **Published:** Jun 14, 2026
- **Last Modified:** Jun 16, 2026

## Description

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

## Affected Products

- LiteSpeed Technologies — cPanel Plugin (2.3)

## References

- [CNA](https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel)
- [CNA](https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-54420)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.44%
- **EPSS Percentile:** 71.4

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Jun 15, 2026
- **Due Date:** Jun 18, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._