LiteSpeed cPanel Plugin Flaw: Early Warning of Exploited Vulnerability
An early warning has been issued regarding a security flaw in the LiteSpeed cPanel Plugin, which appears to be exploited for root privilege escalation. Users of this plugin are advised to take immediate action.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reportedly added a security flaw impacting the LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog. The vulnerability, identified as CVE-2026-54420, allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS. This flaw affects versions of the LiteSpeed cPanel plugin before 2.4.8.
CISA has urged Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by June 18, 2026. LiteSpeed has released security updates and advised users to upgrade to the latest version of the plugin. To check if your server is vulnerable, run the command: `grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry.*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null`. If the command shows output, further investigation is required to rule out false positives.
It is currently under investigation how the vulnerability is being exploited in the wild and whether any attacks have been successful. Users are advised to consult the primary sources for the most up-to-date information and to ensure they have applied the latest security updates.
How 0Day mitigates this
litespeed cpanel plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.