Skip to content
Critical LiteSpeed Flaw Allows Root Access via Shared Hosting Accounts

Critical LiteSpeed Flaw Allows Root Access via Shared Hosting Accounts

First seen 15 Sep 2026, 07:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 08:51 UTC
  • A critical vulnerability in LiteSpeed Web Server Enterprise allows root access to shared hosting accounts.
  • Affected versions include those prior to 6.3.7; administrators are urged to update immediately.
  • This is the third instance of privilege escalation vulnerabilities in LiteSpeed software since May 2026.

A critical vulnerability in LiteSpeed Web Server Enterprise allows low-privilege users on shared-hosting servers to gain root access. This flaw can bypass account isolation controls like CageFS, enabling attackers to access or alter other hosted websites. Affected versions are those prior to 6.3.7, with the patch released on September 11, 2026. cPanel issued an advisory on September 14, urging administrators to update immediately. The advisory does not provide a CVE identifier or indicate whether the flaw has been exploited. This vulnerability marks the third instance since May where LiteSpeed software has allowed root access through cPanel servers. Previous vulnerabilities, CVE-2026-48172 and CVE-2026-54420, were also linked to privilege escalation and confirmed to be actively exploited. As of September 15, 2026, LiteSpeed's download page still lists the previous stable version, 6.3.6.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-21
CVE-2026-48172 published
LiteSpeed disclosed a privilege escalation flaw in its cPanel plugin, actively exploited.
Thehackernews
2026-05-26
CVE-2026-48172 added to CISA KEV
CISA added CVE-2026-48172 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Thehackernews
2026-06-14
CVE-2026-54420 published
LiteSpeed disclosed another privilege escalation flaw in its cPanel plugin, also actively exploited.
Thehackernews
2026-06-15
CVE-2026-54420 added to CISA KEV
CISA added CVE-2026-54420 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Thehackernews
2026-09-11
LiteSpeed releases patch 6.3.7
LiteSpeed published version 6.3.7 to address the critical vulnerability affecting shared-hosting servers.
Thehackernews
2026-09-14
cPanel issues security advisory
cPanel warned of a critical vulnerability in LiteSpeed Web Server Enterprise, urging updates to version 6.3.7.
support.cpanel.net

More articles in this cluster (4)

Following this threat?

Track CloudLinux and CVE-2026-48172 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed