{"id":1325,"date":"2026-06-16T08:09:08","date_gmt":"2026-06-16T08:09:08","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1325"},"modified":"2026-06-16T08:09:08","modified_gmt":"2026-06-16T08:09:08","slug":"cisa-flags-litespeed-cpanel-plugin-flaw-exploited-for-root-privilege-escalation","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1325","title":{"rendered":"CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 16, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Server Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhweJrEaMuAEZCtL6h2H2XMxWOMGzKSktYq9kDvwXAGvIAt39-gz3irXruUA0KVSSupFdIh13o2F5quHfout07-tOHYK334xgNwRq5WcVbfyL5T1i-jYVCGLuVksBYExOncAm72ZuyRacuSG8a1ssx6jrxN8WcQ5Q91gYN3MYh-rWcY_86jVcbvZJbabPR1\/s1700-e365\/litespeed.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/06\/15\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">added<\/a> a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">KEV<\/a>) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026.<\/p>\n<p>The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case of privilege escalation. It allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS.<\/p>\n<p>\u00abLiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux\/CageFS,\u00bb according to a <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-54420\">description<\/a> of the vulnerability in CVE.org.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s currently not known how the vulnerability is being exploited in the wild and if any of those attacks have been successful, but LiteSpeed has <a href=\"https:\/\/blog.litespeedtech.com\/2026\/06\/01\/security-update-for-litespeed-cpanel-plugin-2\/\">urged<\/a> users to run the command below to check if their servers are affected &#8211;<\/p>\n<pre><code>grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' \/usr\/local\/cpanel\/logs\/ \/var\/cpanel\/logs\/ 2&gt;\/dev\/null<\/code><\/pre>\n<p>If the grep command does not show any output, it indicates the server has not been impacted by the issue. If there is any output, LiteSpeed has shared additional indicators to rule out any false positives &#8211;<\/p>\n<ul>\n<li>generateEcCert immediately followed by packageUserSize for the same user (legitimate UI flows don&#8217;t chain these)<\/li>\n<li>7-10 concurrent calls per attempt (legitimate UI does one at a time)<\/li>\n<\/ul>\n<p>Namecheap has been credited with bringing the issue to its attention on May 31, 2026. Users are advised to upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled w\/ cPanel plugin v2.4.8) or higher to patch the vulnerability.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 16, 2026Vulnerability \/ Server Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV)&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1326,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[62,1465,306,128,542,70,1772,1258,305,61],"class_list":["post-1325","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cisa","tag-cpanel","tag-escalation","tag-exploited","tag-flags","tag-flaw","tag-litespeed","tag-plugin","tag-privilege","tag-root"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1325"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1325\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1326"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}