LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Utnyttes aktivt (CISA KEV)
Høy 8.5 CVSS 3.1
Beskrivelse
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Beskrivelsen gjengis slik kilden har publisert den, på engelsk.
Nøkkelfakta
Publisert
2026-06-14
Sist endret
2026-07-23
Tildelt av
cve@mitre.org
CVSS-vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Scoret av
cve@mitre.org
Sannsynlighet for utnyttelse
1.4 %
høyere enn 71 %
av alle kjente sårbarheter
EPSS, neste 30 dager, modell v2026.06.15
Rettelse finnes
Ikke registrert hos kildene
Aktivt utnyttet
CISA førte denne sårbarheten inn i katalogen over kjente utnyttede
sårbarheter 2026-06-15,
med utbedringsfrist 2026-06-18 for amerikanske føderale etater.
Pålagt tiltak: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause t…