Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-54420

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 44.5%
CVSS Severity
CVSS v3 Score 8.5
Proposed Action
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
Ransomware Campaign
Unknown
Products affected by CVE-2026-54420


Contact Us

Shodan ® - All rights reserved