Cyber Alerts
MA-1462.062026: MyCERT Advisory - LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.
- First observed
- 29 Jul 2026
- Last checked
- 01 Aug 2026
- Evidence records
- 1
- Publication state
- Published
What happened?
Current assessment
Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.
Why it matters
Attacker with low-privileged FTP or web shell access can place crafted symlinks to bypass filesystem boundaries. This allows execution of arbitrary code as root, granting full control over the underlying server and all tenant accounts.
Who is affected?
Affected products and groups
- Product: This vulnerability affects all LiteSpeed user-end cPanel plugin versions prior to 2.4.8 (bundled with WHM Plugin version 5.3.2.0) — Product or product group named in the MyCERT advisory.
What should you do now?
Actions from official guidance
For everyone
- CyberSecurity Malaysia encourages users and administrators to review the security updates released by LiteSpeed and apply the necessary security updates provided by the vendor. Official source
Which sources support it?
Evidence and official sources
-
MyCERTOfficial sourceMA-1462.062026: MyCERT Advisory - LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.
Published Just published · Retrieved 01 Aug 2026