Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

The Hacker News by The Hacker News
September 15, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalSep 15, 2026Vulnerability / Web Security

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.

On such servers, many customers’ sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory.

cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11.

The flaw can bypass the controls that keep hosting accounts apart, including CageFS, cPanel said. CageFS is a CloudLinux tool that gives each hosting account a restricted view of the file system, so it cannot see other accounts or the server’s configuration files.

Neither cPanel’s advisory nor LiteSpeed’s release notes describe how the flaw works. LiteSpeed’s announcement of 6.3.7 called it a release with “Security improvements, bug fixes, and more!” Its changelog lists three security changes but does not mention a privilege-escalation flaw, and neither company has said publicly which change fixes it.

The advisory carries no CVE identifier or severity score, and a check of published CVE records on September 15 found none for the flaw. The advisory also does not say whether the flaw has been exploited.

Both cPanel and LiteSpeed give the same command to install 6.3.7 now: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7

The manual update matters because 6.3.7 may not arrive on its own: LiteSpeed said there “may be some delay” before the release reaches auto-update.

As of September 15, LiteSpeed’s download page still listed 6.3.6 as the stable release, alongside a July pre-release build of 6.4.0 (RC1) whose changelog does not list the three security changes. cPanel’s advisory does not say whether the 6.4.0 release candidates are affected.

LiteSpeed’s update documentation says that forcing a specific version with this command stops the server from following its stable update tier, and that administrators can resume automatic stable updates afterward by running touch /usr/local/lsws/autoupdate/follow_stable.

Neither cPanel’s advisory nor LiteSpeed’s release notes offer a workaround for servers that cannot update at once, or indicators for checking whether a server has already been attacked. The advisory names only the Enterprise edition and does not address OpenLiteSpeed, LiteSpeed’s open-source server, for which LiteSpeed had released no matching update as of September 15.

It is the third time since May that a flaw in LiteSpeed software on cPanel servers has been reported to grant a hosting account root access, but the first in the web server itself.

In May and June, LiteSpeed disclosed two such flaws in its user-end cPanel plugin, CVE-2026-48172 and CVE-2026-54420, said both were being actively exploited, and fixed both in the plugin. CISA later added both to its Known Exploited Vulnerabilities catalog, as The Hacker News reported in May and June.

The Hacker News has contacted LiteSpeed, cPanel, and CloudLinux with questions about the flaw.



Source link

The Hacker News

The Hacker News

Next Post

Momax Wins 2026 IFA Innovation Award in Berlin

Recommended.

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data

March 25, 2026
CCS under fire over ‘anti-SME’ supplier requirements for G-Cloud 15 | Computer Weekly

CCS under fire over ‘anti-SME’ supplier requirements for G-Cloud 15 | Computer Weekly

November 18, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio