{"id":13243,"date":"2026-06-01T12:04:41","date_gmt":"2026-06-01T16:04:41","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=13243"},"modified":"2026-06-01T12:04:41","modified_gmt":"2026-06-01T16:04:41","slug":"security-update-for-litespeed-cpanel-plugin-2","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2026\/06\/01\/security-update-for-litespeed-cpanel-plugin-2\/","title":{"rendered":"Security Update for LiteSpeed cPanel Plugin"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-13221\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2026\/05\/lsquic-vuln2.png\" alt=\"LiteSpeed cPanel Plugin Vulnerability\" width=\"1000\" height=\"500\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2026\/05\/lsquic-vuln2.png 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2026\/05\/lsquic-vuln2-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2026\/05\/lsquic-vuln2-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2026\/05\/lsquic-vuln2-600x300.png 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>We have another urgent security update for LiteSpeed\u2019s user-end plugin for cPanel.<\/p>\n<p>Last night we were made aware of a vulnerability affecting our user-end cPanel plugin (LiteSpeed\u2019s WHM plugin was not affected). We patched this vulnerability in v2.4.8.<\/p>\n<p>Please update to the latest version of the cPanel user-end plugin, which is bundled with the WHM plugin..<\/p>\n<p>This Privilege Escalation vulnerability, which was reported to us by the team at Namecheap, has been assigned <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-54420\">CVE-2026-54420<\/a>.<\/p>\n<h2>Impact<\/h2>\n<p>A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux\/CageFS.<\/p>\n<p>This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.<\/p>\n<p>Use the following command to determine if your server has been affected:<\/p>\n<pre>grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' \/usr\/local\/cpanel\/logs\/ \/var\/cpanel\/logs\/ 2&gt;\/dev\/null\n<\/pre>\n<p>If there is no output, then your server has not been affected.<\/p>\n<p>If this command results in any output, the vulnerability <em>may<\/em> have been exploited on your server. There can be false positives, so look for the following to confirm:<\/p>\n<ol>\n<li>Pairing: <code>generateEcCert<\/code> immediately followed by <code>packageUserSize<\/code> for the same user (legitimate UI flows don&#8217;t chain these)<\/li>\n<li>Concurrency: 7\u201310 concurrent calls per attempt (legitimate UI does one at a time)<\/li>\n<li>Same source IP hammering both endpoints<\/li>\n<\/ol>\n<p>To determine any damage done, examine the system logs for any actions taken by the detected IPs. If you need assistance, you may <a href=\"https:\/\/store.litespeedtech.com\/store\/clientarea.php\">contact our support team<\/a>.<\/p>\n<h2>Actions<\/h2>\n<p>We urgently recommend that those using the LiteSpeed user-end plugin for cPanel upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled w\/ cPanel plugin v2.4.8) or higher to patch this vulnerability.<\/p>\n<p>To update the WHM plugin, run this command, which will also update the user-end plugin, if you currently have it installed:<\/p>\n<pre>wget -O- https:\/\/litespeedtech.com\/packages\/cpanel\/lsws_whm_plugin_install.sh | sh\n<\/pre>\n<p>If you cannot upgrade at this time, you can use the following command to remove the user-end plugin and avoid this vulnerability:<\/p>\n<pre>\/usr\/local\/lsws\/admin\/misc\/lscmctl cpanelplugin --uninstall<\/pre>\n<p>Once you&#8217;ve updated the WHM plugin, you can run the following commands, which will reinstall the user-end plugin and turn on autoinstall:<\/p>\n<pre>\/usr\/local\/lsws\/admin\/misc\/lscmctl cpanelplugin --install\n\/usr\/local\/lsws\/admin\/misc\/lscmctl cpanelplugin -autoinstall 1\n<\/pre>\n<h2>Timeline<\/h2>\n<ul>\n<li><strong>May 31, 2026<\/strong>: We were alerted to the original issue.<\/li>\n<li><strong>May 31, 2026<\/strong>: cPanel pushed an <code>uninstall<\/code> command for the user-end plugin<\/li>\n<li><strong>Jun 1, 2026<\/strong>: We released cPanel plugin v2.4.8 and WHM plugin v5.3.2.1<\/li>\n<li><strong>Jun 1, 2026<\/strong>: We applied for a CVE<\/li>\n<li><strong>Jun 14, 2026<\/strong>: <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-54420\">CVE-2026-54420<\/a> was assigned<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>We thank Namecheap for bringing the original issue to our attention. We\u2019d also like to thank the cPanel team for their immediate action in preventing further exploitation on additional servers. The vulnerability has been patched, so if you are keeping your cPanel plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so immediately.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have an urgent security update for LiteSpeed\u2019s user-end plugin for cPanel and WHM plugin. Please upgrade to the latest versions ASAP.<\/p>\n","protected":false},"author":1,"featured_media":13221,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[27,23],"tags":[78],"class_list":["post-13243","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-server","category-security","tag-cpanel"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2026\/05\/lsquic-vuln2.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=13243"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13243\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/13221"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=13243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=13243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=13243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}