Cyber Alerts

MA-1462.062026: MyCERT Advisory - LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

Verified Officially confirmed

Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.

First observed
29 Jul 2026
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.

Why it matters

Attacker with low-privileged FTP or web shell access can place crafted symlinks to bypass filesystem boundaries. This allows execution of arbitrary code as root, granting full control over the underlying server and all tenant accounts.

Who is affected?

Affected products and groups

  • Product: This vulnerability affects all LiteSpeed user-end cPanel plugin versions prior to 2.4.8 (bundled with WHM Plugin version 5.3.2.0) — Product or product group named in the MyCERT advisory.

What should you do now?

Actions from official guidance

For everyone

  1. CyberSecurity Malaysia encourages users and administrators to review the security updates released by LiteSpeed and apply the necessary security updates provided by the vendor. Official source

Which sources support it?

Evidence and official sources

  1. MyCERTOfficial source
    MA-1462.062026: MyCERT Advisory - LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

    Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.

    Published Just published · Retrieved 01 Aug 2026