0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability Patched (blog.litespeedtech.com)

· 67d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • CVE-2026-48172 allows privilege escalation via lsws.redisAble function
  • Active exploitation observed; patch released in cPanel plugin v2.4.7
  • cPanel auto-removed vulnerable plugin on May 19

"LiteSpeed released an urgent security update for its user-end cPanel plugin due to a privilege escalation vulnerability (CVE-2026-48172) that is being actively exploited. The flaw allows any cPanel user to execute arbitrary scripts as root via the lsws.redisAble function. Patched versions: cPanel plugin v2.4.7, WHM plugin v5.3.1.0. Versions v2.3 to v2.4.4 are affected. The WHM plugin was not affected. cPanel automatically removed the vulnerable plugin during nightly updates on May 19."

Discussion Matrix

0 segments

no comments yet.