CISA Warns LiteSpeed cPanel Plugin Flaw Is Being Exploited in Attacks


CISA has added a LiteSpeed cPanel Plugin privilege escalation vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw, tracked as CVE-2026-48172, can let a cPanel user execute scripts with root privileges on affected servers.

The vulnerability affects the LiteSpeed User-End cPanel Plugin before version 2.4.5. According to LiteSpeed’s security update, the issue affects user-end plugin versions between v2.3 and v2.4.4, while the WHM parent plugin itself was not affected.

CISA’s KEV catalog lists the bug as actively exploited and gives federal agencies until May 29, 2026, to apply vendor mitigations or stop using the affected product. Hosting providers, MSPs, and shared-hosting operators should treat the flaw as urgent because a single low-level account can create server-wide risk.

What CVE-2026-48172 Allows Attackers to Do

CVE-2026-48172 is an incorrect privilege assignment flaw tied to the user-end cPanel plugin. In vulnerable versions, an authenticated cPanel user can abuse the plugin’s Redis enable or disable function to run scripts with elevated privileges.

The NVD entry says LiteSpeed User-End cPanel Plugin versions before 2.4.5 allow privilege escalation, possibly to root, and notes exploitation in the wild in May 2026. That makes the vulnerability especially dangerous in hosting environments where many customers share the same server.

The GitHub Advisory Database also links the issue to mishandling of Redis enable or disable features and recommends checking cPanel logs for signs that the vulnerable function was called.

Why Shared Hosting Providers Face Higher Risk

Shared hosting platforms often place many customer accounts on one server. If one account gets compromised, an attacker may use that account as the starting point for privilege escalation.

In this case, the danger is not limited to the account that the attacker controls. If exploitation succeeds, the attacker may gain root-level execution on the server, which can expose other tenants, hosted websites, databases, configuration files, mail data, and credentials.

Risk areaPossible impactWho should act
Shared hosting serversOne compromised cPanel account may lead to root accessHosting providers and MSPs
Customer websitesAttackers may modify files, inject malware, or add backdoorsSite owners and platform admins
Server configurationAttackers may alter services or persistence settingsSystem administrators
Customer dataCross-tenant data exposure may become possibleSecurity and compliance teams
Incident responseExploitation may require log review and forensic checksSOC and hosting support teams

LiteSpeed Has Released a Fix

LiteSpeed says it patched the original vulnerability in cPanel plugin v2.4.5. After a broader review, the company released cPanel plugin v2.4.7 bundled with WHM Plugin v5.3.1.0 and recommends that users upgrade to that version or later.

Admins who cannot upgrade immediately can remove the user-end plugin to avoid exposure. LiteSpeed provides an uninstall command for that fallback path, but patching remains the cleaner long-term fix for environments that need the plugin.

The company also said cPanel took action on May 19 to push an uninstall command for the user-end plugin. That helped limit further exposure while LiteSpeed completed its plugin review and released updated versions.

How to Check for Possible Exploitation

Admins should check whether the vulnerable Redis function appears in cPanel logs. The GitHub advisory recommends searching logs for the following pattern:

cpanel_jsonapi_func=redisAble

If the search returns no output, the advisory says the server has not shown evidence of exploitation through that specific log pattern. If there is output, administrators should examine the listed IP addresses, block suspicious sources, and review system logs to determine what actions those IPs performed.

  • Upgrade to LiteSpeed WHM Plugin v5.3.1.0 bundled with cPanel plugin v2.4.7 or later.
  • If upgrading is not possible, uninstall the LiteSpeed user-end cPanel plugin until a fix can be applied.
  • Search cPanel logs for cpanel_jsonapi_func=redisAble.
  • Review returned IP addresses and block unauthorized sources.
  • Inspect system logs for root-level script execution or configuration changes.
  • Check for new users, cron jobs, SSH keys, web shells, and modified service files.
  • Rotate credentials for affected hosting accounts and administrative users if exploitation is suspected.
  • Notify customers if evidence suggests cross-tenant access or data exposure.

CISA Sets a Short Remediation Window

The short KEV deadline shows how seriously CISA is treating the issue. Under Binding Operational Directive 22-01, U.S. federal civilian agencies must remediate known exploited vulnerabilities by the assigned due date.

CISA lists the required action as applying vendor mitigations, following BOD 22-01 guidance for cloud services, or discontinuing use of the product if mitigations are not available. Although the deadline applies directly to federal agencies, private organizations often use KEV listings to prioritize emergency patching.

The NVD record also notes that the recommended minimum version is 2.4.7, matching LiteSpeed’s latest recommended plugin bundle rather than only the first patched version.

Why This Vulnerability Matters

Attackers increasingly target hosting control panels and server management tools because those systems sit above many customer environments. A flaw in one plugin can create a path into many websites and services at once.

For hosting providers, the priority should be patching first, then hunting for signs of exploitation. A clean upgrade protects against future attempts, but it does not prove that attackers did not already use the flaw before the patch was applied.

Security teams should also review how cPanel plugins are deployed, updated, and monitored. Third-party or bundled server plugins should follow the same emergency patch process as operating systems, web servers, and exposed admin panels.

FAQ

What is CVE-2026-48172?

CVE-2026-48172 is a privilege escalation vulnerability in the LiteSpeed User-End cPanel Plugin. It can allow an authenticated cPanel user to execute arbitrary scripts with root privileges on affected servers.

Which LiteSpeed plugin versions are affected?

The flaw affects LiteSpeed User-End cPanel Plugin versions from v2.3 through v2.4.4. LiteSpeed patched the original issue in v2.4.5 and recommends upgrading to WHM Plugin v5.3.1.0 bundled with cPanel plugin v2.4.7 or later.

Is the LiteSpeed WHM parent plugin affected?

LiteSpeed says the WHM parent plugin was not affected by the original vulnerability. However, the fixed user-end cPanel plugin is bundled with the updated WHM Plugin v5.3.1.0, so admins should upgrade to the latest bundle.

How can admins check for exploitation?

Admins can search cPanel logs for cpanel_jsonapi_func=redisAble. If the search returns output, they should review the listed IP addresses, block suspicious sources, and inspect system logs for actions performed by those IPs.

What should hosting providers do now?

Hosting providers should upgrade immediately, remove the user-end plugin if they cannot patch, review logs for exploitation, inspect servers for persistence, and rotate credentials if compromise is suspected.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages