- A critical vulnerability in LiteSpeed Web Server Enterprise could allow low-privilege users to gain root access on shared-hosting servers.
- cPanel urged administrators to update to version 6.3.7, which was released on September 11, as the flaw bypasses security controls like CageFS.
- No CVE identifier, severity score, or workaround has been published, and the flaw’s exploitation status remains unknown.
On September 14, cPanel warned that a critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, according to an advisory. On such servers, an attacker with a single hosting account could exploit the flaw to access or alter other sites and the server itself.
cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11. The flaw can bypass the controls that keep hosting accounts apart, including CageFS, a CloudLinux tool that restricts each account’s view of the file system.
Neither cPanel’s advisory nor LiteSpeed’s release notes describe how the flaw works. The advisory carries no CVE identifier or severity score, and a check of published CVE records on September 15 found none for the flaw.
Both cPanel and LiteSpeed give the same command to install 6.3.7: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. The manual update matters because LiteSpeed said there “may be some delay” before the release reaches auto-update.
As of September 15, LiteSpeed’s download page still listed 6.3.6 as the stable release. Neither company has offered a workaround for servers that cannot update at once, or indicators for checking whether a server has already been attacked.
It is the third time since May that a flaw in LiteSpeed software on cPanel servers has been reported to grant a hosting account root access, but the first in the web server itself. In May and June, LiteSpeed disclosed two such flaws in its user-end cPanel plugin, CVE-2026-48172 and CVE-2026-54420, said both were being actively exploited, and fixed both in the plugin.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
