HomeSecurityLiteSpeed ​​Enterprise: Critical vulnerability allows root access to shared servers

LiteSpeed ​​Enterprise: Critical vulnerability allows root access to shared servers

A critical vulnerability in LiteSpeed ​​Web Server Enterprise puts shared hosting server administrators at serious risk, as it allows a low-privileged user to gain root access to the server. cPanel issued an official advisory on September 14, 2026, urging administrators to immediately update. This is one of the most serious vulnerabilities reported in the LiteSpeed ​​Enterprise in recent months, and the lack of details on how to exploit it makes the situation even more worrying.

LiteSpeed ​​Enterprise critical root access vulnerability shared hosting

In shared hosting environments , multiple customers host their websites on the same physical or virtual machine. This means that an attacker with even one hosting account could exploit the vulnerability to access other customers' data, modify files, or even take full control of the server. The impact of such an attack could be devastating for both hosting providers and end users.

The vulnerability affects versions prior to 6.3.7 of LiteSpeed ​​Web Server Enterprise. LiteSpeed ​​released version 6.3.7 on September 11, 2026, three days before the cPanel. However, the company warned that there may be a delay in distribution via the automatic update mechanism, making manual installation necessary for those who want immediate protection.

See also: CISA: Vulnerability in LiteSpeed ​​cPanel Plugin allows privilege escalation

LiteSpeed ​​Enterprise: What exactly does the vulnerability allow?

According to the cPanel announcement , the vulnerability can bypass the isolation mechanisms that separate hosting accounts from each other . One of the most important tools that is bypassed is CageFS , a CloudLinux system that provides each hosting account with a limited “image” of the file system. With CageFS, each user sees only their own files and does not have access to files of other accounts or to the server’s configuration files. Bypassing this mechanism is a particularly serious threat, as CageFS is considered one of the basic layers of security in shared hosting environments.

Neither the cPanel announcement nor LiteSpeed ’s release notes describe exactly how the vulnerability works. LiteSpeed’s announcement for version 6.3.7 simply described it as a release with “ security improvements, bug fixes, and more .” The changelog lists three security-related changes, but does not explicitly mention a privilege escalation vulnerability . This lack of transparency makes it difficult for administrators to assess the risk and make informed decisions.

It is worth noting that the vulnerability has not yet received a CVE identifier or severity rating. A check of published CVE on September 15, 2026 did not reveal any relevant identifiers. Also, neither company has publicly stated whether the vulnerability has already been exploited, which leaves open the question of whether there are already victims.

LiteSpeed ​​Enterprise - SecNews.gr

LiteSpeed ​​Enterprise: How to Protect Yourself Instantly

Both cPanel and LiteSpeed ​​recommend installing version 6.3.7 via the following command:

/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7

See also: CISA: LiteSpeed ​​cPanel Plugin Vulnerability in KEV Catalog

The manual update is necessary because LiteSpeed ​​has warned that there may be a delay before version 6.3.7 is made available through the automatic update mechanism. As of September 15, 2026, the LiteSpeed ​​download page still lists version 6.3.6 as the stable release, along with a July pre-release 6.4.0 (RC1) , the changelog of which does not include the three security changes.

It is also important to note that neither company has provided a workaroundforservers that cannot be updated immediately, nor any Indicatorsof Compromisefor administrators to check if their server has already been attacked.

Plesk for Linux risk in shared hosting

Additionally, the announcement only refers to the Enterprise version of LiteSpeed ​​Web Server and not OpenLiteSpeed, the open-source version of the server. To date, LiteSpeed ​​has not released a corresponding update for OpenLiteSpeed, leaving the question of whether this version is also affected unanswered.

This is the third time since May 2026 that a vulnerability has been reported in LiteSpeed ​​software on cPanel servers . However, it is the first time that the vulnerability is found in the web server itself and not in a plugin. In May and June 2026, LiteSpeed ​​disclosed two such vulnerabilities in its cPanel plugin , with identifiers CVE-2026-48172 and CVE-2026-54420 . CISA later added both to the Known Exploited Vulnerabilities (KEV) list , as reported by The Hacker News.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: LiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

For administrators who cannot immediately apply the update, it is recommended to monitor server logsforsuspicious activity, implement additional layers of security such as Web Application Firewall (WAF), and restrict access to administrative interfaces. It is also important to check if hosting accounts have unusual permissions or if there are new files in sensitive system locations.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS