[KRİTİK]⚠️ Security Advisory: LiteSpeed cPanel plugin
⚠️ Security Advisory: LiteSpeed cPanel plugin
UPGRADE TO LiteSpeed WHM plugin v5.3.2.1
URGENT: Patch LiteSpeed WHM Plugin Now. Root Privilege Escalation (CVE-2026-54420)
A privilege-escalation vulnerability in the LiteSpeed cPanel/WHM plugin CVE-2026-54420 (CVSS 8.5) has been added to CISA's Known Exploited Vulnerabilities catalog. We strongly recommend patching as soon as possible.
The risk:
On shared hosting servers running CloudLinux/CageFS, the flaw allows a user with FTP or web shell access to escalate privileges to root by mishandling user-provided symlinks. In practice, that means a single compromised or malicious account could gain full control of the server.
What's affected:
LiteSpeed cPanel plugin before v2.4.8 (as distributed in LiteSpeed WHM Plugin before v5.3.2.0).
⚠️⚠️⚠️ Required action:
Upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled with cPanel plugin v2.4.8) or higher.
Checking whether a server was targeted:
LiteSpeed has provided a command to scan your logs for indicators:
SHELLgrep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null
No output means the server shows no signs of this activity. If there is output, the following patterns point to a likely exploitation attempt (rather than normal use):
➡️ if generateEcCert immediately followed by packageUserSize for the same user (legitimate UI flows don't chain these)
➡️ and if 7-10 concurrent calls per attempt (legitimate UI does one at a time)
✅ The update button should now be available directly within the LiteSpeed's WHM plugin interface.
@LicensePOW
https://licensepow.com