LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
LiteSpeed · cPanel Plugin
Date added (CISA)
2026-06-15
Remediation due
2026-06-18
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.