High CVE-2026-54420, CVE-2026-87886 — Two control-panel plugins common on shared hosting servers let a customer account escalate to root: a LiteSpeed cPanel plugin symlink bug and insecure permissions in Acronis Backup for cPanel, Plesk and DirectAdmin. Fixed versions for hosts.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: On shared hosting, every customer's account is a potential attacker. Two exploited plugin bugs let one hosting account break out: the LiteSpeed cPanel plugin before 2.4.8 mishandles user-supplied symlinks even under CloudLinux/CageFS, and Acronis Backup plugins for cPanel/WHM, Plesk and DirectAdmin had insecure file permissions allowing local privilege escalation. Hosts should update both now.
| CVE-2026-54420 | LiteSpeed cPanel plugin < 2.4.8 (LiteSpeed WHM PlugIn < 5.3.2.0): symlink handling → cross-account/privileged file access. CVSS 8.5. Exploited since May 2026; KEV 2026-06-15 |
|---|---|
| CVE-2026-87886 | Acronis Backup plugins: insecure default permissions → local privilege escalation. CVSS 7.8. KEV 2026-09-16 |
| Acronis fixed | cPanel & WHM 1.9.3.1021 · Plesk 1.8.11.638 · DirectAdmin 1.2.3.238 |
| Who's affected | Hosting providers and anyone running a multi-user control panel server |
On a shared server, “local user” means any customer, or anyone who has hacked any customer’s WordPress site. Root on the server means every site and mailbox on it.
/usr/local/lsws/admin/misc/lscmctl cpanelplugin --install.find /home/*/public_html -type l -lname '/*' 2>/dev/null | head/var/log/secure, WHM’s access log, and new root-level cron jobs or SSH keys.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.