Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Shared Hosting Alert: LiteSpeed cPanel Plugin CVE-2026-54420 and Acronis Backup Plugins CVE-2026-87886 Exploited

High CVE-2026-54420, CVE-2026-87886 — Two control-panel plugins common on shared hosting servers let a customer account escalate to root: a LiteSpeed cPanel plugin symlink bug and insecure permissions in Acronis Backup for cPanel, Plesk and DirectAdmin. Fixed versions for hosts.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: On shared hosting, every customer's account is a potential attacker. Two exploited plugin bugs let one hosting account break out: the LiteSpeed cPanel plugin before 2.4.8 mishandles user-supplied symlinks even under CloudLinux/CageFS, and Acronis Backup plugins for cPanel/WHM, Plesk and DirectAdmin had insecure file permissions allowing local privilege escalation. Hosts should update both now.

CVE-2026-54420LiteSpeed cPanel plugin < 2.4.8 (LiteSpeed WHM PlugIn < 5.3.2.0): symlink handling → cross-account/privileged file access. CVSS 8.5. Exploited since May 2026; KEV 2026-06-15
CVE-2026-87886Acronis Backup plugins: insecure default permissions → local privilege escalation. CVSS 7.8. KEV 2026-09-16
Acronis fixedcPanel & WHM 1.9.3.1021 · Plesk 1.8.11.638 · DirectAdmin 1.2.3.238
Who's affectedHosting providers and anyone running a multi-user control panel server

What the bugs are

  • CVE-2026-54420 (LiteSpeed): a user with FTP or web-shell access to their own hosting account can plant symlinks that the LiteSpeed cPanel plugin follows with higher privileges, even on servers isolated with CloudLinux and CageFS. LiteSpeed says this was exploited in the wild in May 2026, before the fix.
  • CVE-2026-87886 (Acronis): the Acronis Backup integrations for cPanel & WHM, Plesk and DirectAdmin on Linux installed files with insecure permissions, letting a local user escalate privileges.

On a shared server, “local user” means any customer, or anyone who has hacked any customer’s WordPress site. Root on the server means every site and mailbox on it.

Am I affected?

  • LiteSpeed: WHM → Plugins → LiteSpeed Web Server shows the plugin version. You need cPanel plugin 2.4.8+ / WHM plugin 5.3.2.0+.
  • Acronis: check the extension/plugin version in WHM, Plesk Extensions, or DirectAdmin plugins against the fixed builds above.

How to patch

  • LiteSpeed: update from WHM → LiteSpeed Web Server → Update/Upgrade WHM plugin, or from the shell: /usr/local/lsws/admin/misc/lscmctl cpanelplugin --install.
  • Acronis: update the extension from the panel’s extension/plugin manager or reinstall the latest build from Acronis.

Check for abuse

  • Look for symlinks in customer home directories pointing outside their own tree: find /home/*/public_html -type l -lname '/*' 2>/dev/null | head
  • Review /var/log/secure, WHM’s access log, and new root-level cron jobs or SSH keys.
  • On compromise, assume all accounts on the server are affected; rotate cPanel, database and email passwords server-wide.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories