LiteSpeed Web Server Enterprise privilege-escalation flaw
Vulnerability
Summary
Hide ▲
Show ▼
A critical privilege-escalation flaw in LiteSpeed Web Server Enterprise can let a low-privilege website user gain root access on shared-hosting servers. The issue affects versions before 6.3.7 and can break isolation between hosted accounts, exposing other sites and the server itself. cPanel and LiteSpeed have directed administrators to update to 6.3.7 as the fix, while public details on exploit method, CVE assignment, and active abuse remain unavailable.
Related Happenings
CPanel & WHM parked/addon domain root code execution flaw (CVE-2026-65643)
Vulnerability
H score9
First: 28.08.2026 12:45
Last: 28.08.2026 12:45
Sources 1
About this happening:
cPanel has patched CVE-2026-65643 in cPanel & WHM, a flaw in parked and addon domain handling that could let an authenticated user reach root code execution on all s...
CPanel & WHM parked/addon domain root code execution flaw (CVE-2026-65643)
VulnerabilityAbout this happening: cPanel has patched CVE-2026-65643 in cPanel & WHM, a flaw in parked and addon domain handling that could let an authenticated user reach root code execution on all s...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector Action
H score36
First: 16.06.2026 13:47
Last: 16.06.2026 13:47
Sources 1
About this happening:
CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector ActionAbout this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/Mitigation
H score38
First: 16.06.2026 08:41
Last: 16.06.2026 08:41
Sources 1
About this happening:
CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/MitigationAbout this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
LiteSpeed User-End cPanel Plugin root script execution security flaw (CVE-2026-48172)
Vulnerability
H score48
First: 23.05.2026 10:35
Last: 23.05.2026 10:35
Sources 1
About this happening:
CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin is now actively exploited, creating root-level arbitrary script execution risk for exposed cPanel systems. T...
LiteSpeed User-End cPanel Plugin root script execution security flaw (CVE-2026-48172)
VulnerabilityAbout this happening: CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin is now actively exploited, creating root-level arbitrary script execution risk for exposed cPanel systems. T...
Timeline
-
15.09.2026 09:52 1 articles · 3h ago
LiteSpeed publishes 6.3.7 for Web Server Enterprise
Mitigation Patch UpdateLiteSpeed released version 6.3.7 for LiteSpeed Web Server Enterprise, the update tied to a critical privilege-escalation flaw affecting versions before 6.3.7 on shared-hosting servers. LiteSpeed also warned that the release may take time to reach auto-update, so administrators might need to install it manually.
Show sources
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — thehackernews.com — 15.09.2026 09:52
-
15.09.2026 09:52 2 articles · 3h ago
cPanel warns of root-access flaw in LiteSpeed Web Server Enterprise
Initial DisclosurecPanel warned that a critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user on a shared-hosting server gain root access and bypass isolation controls such as CageFS, exposing other hosted sites and the server itself. The advisory said the flaw affects versions before 6.3.7 and did not provide a CVE, severity score, exploit details, or a workaround.
Show sources
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — thehackernews.com — 15.09.2026 09:52
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — thehackernews.com — 15.09.2026 09:52