LiteSpeed cPanel Plugin Vulnerability CVE-2026-48172 Allows Privilege Escalation (nvd.nist.gov)
0xBASE INTEL BRIEF
- Privilege escalation (possibly to root) in LiteSpeed cPanel plugin before 2.4.5
- Actively exploited since May 2026
- CVSS 4.0 score 10.0 (Critical)
- Update to version 2.4.7 recommended
"A critical privilege escalation vulnerability in the LiteSpeed cPanel plugin before version 2.4.5 (CVE-2026-48172) is being actively exploited as of May 2026. The flaw allows attackers to gain root-level access. Detection involves searching logs for a specific string; updates to version 2.4.7 are recommended."
no comments yet.