Executive brief
A vulnerability in the LiteSpeed cPanel plugin allows malicious users on a shared hosting server to bypass security restrictions. By using specially crafted file links, an attacker with basic FTP or web shell access can gain unauthorized access to files belonging to other users or the system. This flaw has been actively exploited in the wild to compromise shared hosting environments.
Technical details
The LiteSpeed cPanel plugin (versions before 2.4.8) is vulnerable to a symbolic link (symlink) following attack (CWE-61). The vulnerability exists in how the plugin handles files provided by users with FTP or web shell access, specifically in environments using CloudLinux/CageFS. An attacker with low-privileged access can create symlinks that point to sensitive files outside of their restricted environment, potentially leading to a full system compromise or cross-user data theft. This issue was reported as being exploited in the wild in May 2026. The vulnerability is addressed in LiteSpeed cPanel plugin 2.4.8 and LiteSpeed WHM PlugIn 5.3.2.0.
Affected products
- LiteSpeed cPanel Plugin before 2.4.8
- LiteSpeed WHM PlugIn before 5.3.2.0
Timeline
- 2026-05: exploited: Exploited in the wild.
- 2026-06-01: patched: Security update released by vendor.
- 2026-06-15: advisory: NVD publication date.