CISA Warns LiteSpeed cPanel Plugin Flaw Is Being Exploited in Attacks
CISA has added a LiteSpeed cPanel Plugin privilege escalation vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw, tracked as CVE-2026-48172, can let a cPanel user execute scripts with root privileges on affected servers.
The vulnerability affects the LiteSpeed User-End cPanel Plugin before version 2.4.5. According to LiteSpeed’s security update, the issue affects user-end plugin versions between v2.3 and v2.4.4, while the WHM parent plugin itself was not affected.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
CISA’s KEV catalog lists the bug as actively exploited and gives federal agencies until May 29, 2026, to apply vendor mitigations or stop using the affected product. Hosting providers, MSPs, and shared-hosting operators should treat the flaw as urgent because a single low-level account can create server-wide risk.
What CVE-2026-48172 Allows Attackers to Do
CVE-2026-48172 is an incorrect privilege assignment flaw tied to the user-end cPanel plugin. In vulnerable versions, an authenticated cPanel user can abuse the plugin’s Redis enable or disable function to run scripts with elevated privileges.
The NVD entry says LiteSpeed User-End cPanel Plugin versions before 2.4.5 allow privilege escalation, possibly to root, and notes exploitation in the wild in May 2026. That makes the vulnerability especially dangerous in hosting environments where many customers share the same server.
The GitHub Advisory Database also links the issue to mishandling of Redis enable or disable features and recommends checking cPanel logs for signs that the vulnerable function was called.
Why Shared Hosting Providers Face Higher Risk
Shared hosting platforms often place many customer accounts on one server. If one account gets compromised, an attacker may use that account as the starting point for privilege escalation.
In this case, the danger is not limited to the account that the attacker controls. If exploitation succeeds, the attacker may gain root-level execution on the server, which can expose other tenants, hosted websites, databases, configuration files, mail data, and credentials.
| Risk area | Possible impact | Who should act |
|---|---|---|
| Shared hosting servers | One compromised cPanel account may lead to root access | Hosting providers and MSPs |
| Customer websites | Attackers may modify files, inject malware, or add backdoors | Site owners and platform admins |
| Server configuration | Attackers may alter services or persistence settings | System administrators |
| Customer data | Cross-tenant data exposure may become possible | Security and compliance teams |
| Incident response | Exploitation may require log review and forensic checks | SOC and hosting support teams |
LiteSpeed Has Released a Fix
LiteSpeed says it patched the original vulnerability in cPanel plugin v2.4.5. After a broader review, the company released cPanel plugin v2.4.7 bundled with WHM Plugin v5.3.1.0 and recommends that users upgrade to that version or later.
Admins who cannot upgrade immediately can remove the user-end plugin to avoid exposure. LiteSpeed provides an uninstall command for that fallback path, but patching remains the cleaner long-term fix for environments that need the plugin.
The company also said cPanel took action on May 19 to push an uninstall command for the user-end plugin. That helped limit further exposure while LiteSpeed completed its plugin review and released updated versions.
How to Check for Possible Exploitation
Admins should check whether the vulnerable Redis function appears in cPanel logs. The GitHub advisory recommends searching logs for the following pattern:
cpanel_jsonapi_func=redisAble
If the search returns no output, the advisory says the server has not shown evidence of exploitation through that specific log pattern. If there is output, administrators should examine the listed IP addresses, block suspicious sources, and review system logs to determine what actions those IPs performed.
Recommended Response Steps
- Upgrade to LiteSpeed WHM Plugin v5.3.1.0 bundled with cPanel plugin v2.4.7 or later.
- If upgrading is not possible, uninstall the LiteSpeed user-end cPanel plugin until a fix can be applied.
- Search cPanel logs for
cpanel_jsonapi_func=redisAble. - Review returned IP addresses and block unauthorized sources.
- Inspect system logs for root-level script execution or configuration changes.
- Check for new users, cron jobs, SSH keys, web shells, and modified service files.
- Rotate credentials for affected hosting accounts and administrative users if exploitation is suspected.
- Notify customers if evidence suggests cross-tenant access or data exposure.
CISA Sets a Short Remediation Window
The short KEV deadline shows how seriously CISA is treating the issue. Under Binding Operational Directive 22-01, U.S. federal civilian agencies must remediate known exploited vulnerabilities by the assigned due date.
CISA lists the required action as applying vendor mitigations, following BOD 22-01 guidance for cloud services, or discontinuing use of the product if mitigations are not available. Although the deadline applies directly to federal agencies, private organizations often use KEV listings to prioritize emergency patching.
The NVD record also notes that the recommended minimum version is 2.4.7, matching LiteSpeed’s latest recommended plugin bundle rather than only the first patched version.
Why This Vulnerability Matters
Attackers increasingly target hosting control panels and server management tools because those systems sit above many customer environments. A flaw in one plugin can create a path into many websites and services at once.
For hosting providers, the priority should be patching first, then hunting for signs of exploitation. A clean upgrade protects against future attempts, but it does not prove that attackers did not already use the flaw before the patch was applied.
Security teams should also review how cPanel plugins are deployed, updated, and monitored. Third-party or bundled server plugins should follow the same emergency patch process as operating systems, web servers, and exposed admin panels.
FAQ
CVE-2026-48172 is a privilege escalation vulnerability in the LiteSpeed User-End cPanel Plugin. It can allow an authenticated cPanel user to execute arbitrary scripts with root privileges on affected servers.
The flaw affects LiteSpeed User-End cPanel Plugin versions from v2.3 through v2.4.4. LiteSpeed patched the original issue in v2.4.5 and recommends upgrading to WHM Plugin v5.3.1.0 bundled with cPanel plugin v2.4.7 or later.
LiteSpeed says the WHM parent plugin was not affected by the original vulnerability. However, the fixed user-end cPanel plugin is bundled with the updated WHM Plugin v5.3.1.0, so admins should upgrade to the latest bundle.
Admins can search cPanel logs for cpanel_jsonapi_func=redisAble. If the search returns output, they should review the listed IP addresses, block suspicious sources, and inspect system logs for actions performed by those IPs.
Hosting providers should upgrade immediately, remove the user-end plugin if they cannot patch, review logs for exploitation, inspect servers for persistence, and rotate credentials if compromise is suspected.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages