HackMyIP
← Back to News
2026-09-15 The Hacker News

LiteSpeed Enterprise Flaw Allows Root Access on Shared Hosting Servers

VulnerabilityZero-DayCloud Security

A critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privilege hosting account to escalate to root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On shared servers where multiple customers' websites run on a single machine, an attacker controlling just one account could exploit the flaw to access or modify other tenants' sites and the underlying system. The vulnerability bypasses CageFS, the CloudLinux feature that gives each hosting account an isolated view of the filesystem to prevent cross-account visibility.

The flaw affects LiteSpeed Enterprise versions prior to 6.3.7, which LiteSpeed released on September 11. Neither cPanel's advisory nor LiteSpeed's release notes describe the technical mechanism, and the 6.3.7 changelog lists only three generic "security improvements" without identifying which fix addresses the privilege-escalation issue. The advisory carries no CVE identifier or CVSS severity score, and a check of published CVE records on September 15 found no entry for the flaw. Administrators are urged to update immediately with the command /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7, because LiteSpeed has warned of possible delays before 6.3.7 reaches auto-update channels. Shared-hosting operators can also run a port scanner to verify which LiteSpeed management interfaces are exposed to the public internet.

The advisory does not address OpenLiteSpeed, LiteSpeed's open-source server, and no matching update had been published for that edition as of September 15. No workaround is offered for servers that cannot update at once, and cPanel provided no indicators of compromise to help administrators determine whether their systems have already been breached. Administrators who rely on LiteSpeed-terminated TLS should also verify their certificate posture with an SSL/TLS checker while planning the upgrade.

This is the third LiteSpeed-related cPanel flaw reported since May to grant a hosting account root-level access, following CVE-2026-48172 and CVE-2026-54440 in the user-end cPanel plugin, both of which were reportedly exploited in the wild. Hosting providers and tenant customers are advised to perform a privacy checkup across affected environments and treat any unpatched LiteSpeed Enterprise instance as high risk until the 6.3.7 upgrade has been confirmed.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →