Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

The Hacker News by The Hacker News
September 15, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalSep 15, 2026Vulnerability / Web Security

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.

On such servers, many customers’ sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory.

cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11.

The flaw can bypass the controls that keep hosting accounts apart, including CageFS, cPanel said. CageFS is a CloudLinux tool that gives each hosting account a restricted view of the file system, so it cannot see other accounts or the server’s configuration files.

Neither cPanel’s advisory nor LiteSpeed’s release notes describe how the flaw works. LiteSpeed’s announcement of 6.3.7 called it a release with “Security improvements, bug fixes, and more!” Its changelog lists three security changes but does not mention a privilege-escalation flaw, and neither company has said publicly which change fixes it.

The advisory carries no CVE identifier or severity score, and a check of published CVE records on September 15 found none for the flaw. The advisory also does not say whether the flaw has been exploited.

Both cPanel and LiteSpeed give the same command to install 6.3.7 now: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7

The manual update matters because 6.3.7 may not arrive on its own: LiteSpeed said there “may be some delay” before the release reaches auto-update.

As of September 15, LiteSpeed’s download page still listed 6.3.6 as the stable release, alongside a July pre-release build of 6.4.0 (RC1) whose changelog does not list the three security changes. cPanel’s advisory does not say whether the 6.4.0 release candidates are affected.

LiteSpeed’s update documentation says that forcing a specific version with this command stops the server from following its stable update tier, and that administrators can resume automatic stable updates afterward by running touch /usr/local/lsws/autoupdate/follow_stable.

Neither cPanel’s advisory nor LiteSpeed’s release notes offer a workaround for servers that cannot update at once, or indicators for checking whether a server has already been attacked. The advisory names only the Enterprise edition and does not address OpenLiteSpeed, LiteSpeed’s open-source server, for which LiteSpeed had released no matching update as of September 15.

It is the third time since May that a flaw in LiteSpeed software on cPanel servers has been reported to grant a hosting account root access, but the first in the web server itself.

In May and June, LiteSpeed disclosed two such flaws in its user-end cPanel plugin, CVE-2026-48172 and CVE-2026-54420, said both were being actively exploited, and fixed both in the plugin. CISA later added both to its Known Exploited Vulnerabilities catalog, as The Hacker News reported in May and June.

The Hacker News has contacted LiteSpeed, cPanel, and CloudLinux with questions about the flaw.



Source link

The Hacker News

The Hacker News

Next Post

Momax Wins 2026 IFA Innovation Award in Berlin

Recommended.

Fed Governor Lisa Cook, in first policy speech since Trump suit, says she’s undecided on Dec. rate cut

Fed Governor Lisa Cook, in first policy speech since Trump suit, says she’s undecided on Dec. rate cut

November 3, 2025
GomSpace signs 7.6 MEUR contract with VirtuaLabs for a satellite cluster for Radio Frequency space-based environment monitoring

GomSpace signs 7.6 MEUR contract with VirtuaLabs for a satellite cluster for Radio Frequency space-based environment monitoring

March 4, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio