{"id":1023,"date":"2026-05-23T08:08:56","date_gmt":"2026-05-23T08:08:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1023"},"modified":"2026-05-23T08:08:56","modified_gmt":"2026-05-23T08:08:56","slug":"litespeed-cpanel-plugin-cve-2026-48172-exploited-to-run-scripts-as-root","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1023","title":{"rendered":"LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 23, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjM0W1UqsbcZ-8IV_n8ov3V24MQ74VaKe3auGFWNunDUfubEBeKEGREuFjC9-i7H_fLfSwFQQ5wqe8bhVWvAUVC_8U5AQg1c1Qbe-M7bSjuWCwcjTRrc2Du7L0Tm-NKO7ErhPUTR7YS6b1vkpmbYS1VaClWUGOvGe4cxv-jHkQFZMXbSDLfBiF7FFwd7Nfe\/s1700-e365\/lightspeed.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild.<\/p>\n<p>The flaw, tracked as <b><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48172\" target=\"_blank\">CVE-2026-48172<\/a><\/b> (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.<\/p>\n<p>\u00abAny cPanel user (including an attacker or a compromised account) may exploit the lsws.redisAble function to execute arbitrary scripts as root,\u00bb LiteSpeed <a href=\"https:\/\/blog.litespeedtech.com\/2026\/05\/21\/security-update-for-litespeed-cpanel-plugin\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>The vulnerability impacts all versions of the plugin between 2.3 and 2.4.4. LiteSpeed&#8217;s WHM plugin is not impacted. The issue has been addressed in version 2.4.5. Security researcher David Strydom has been credited with discovering and reporting the flaw.<\/p>\n<p>LiteSpeed noted that the \u00abvulnerability is being actively exploited,\u00bb but refrained from sharing additional details. It has shared the following indicator of compromise &#8211;<\/p>\n<pre><code>\ngrep -rE \"cpanel_jsonapi_func=redisAble\" \/var\/cpanel\/logs \/usr\/local\/cpanel\/logs\/ 2&gt;\/dev\/null\n<\/code><\/pre>\n<p>If running the aforementioned \u00abgrep\u00bb command does not produce any output, the server is not affected. However, if there is any output, users are advised to examine the IP addresses in the list and determine if they are legitimate, and if not, block them.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Following a security review of its cPanel and WHM plugins in the wake of the vulnerability, LiteSpeed said it has patched additional potential attack vectors in both plugins and released cPanel plugin version 2.4.7 bundled with WHM plugin version 5.3.1.0.<\/p>\n<p>Users are advised to upgrade to LiteSpeed WHM Plugin version 5.3.1.0, which is bundled with cPanel plugin v2.4.7 or higher, to patch the vulnerability. If immediate patching is not an option, it&#8217;s recommended to remove the user-end plugin by running the below command &#8211;<\/p>\n<pre><code>\n\/usr\/local\/lsws\/admin\/misc\/lscmctl cpanelplugin --uninstall\n<\/code><\/pre>\n<p>The development comes weeks after a critical cPanel vulnerability (CVE-2026-41940, CVSS score: 9.8) was identified as actively exploited by unknown threat actors to deploy Mirai botnet variants and a ransomware strain called Sorry.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 23, 2026Vulnerability \/ Web Security A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1024,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1465,1773,128,1772,1258,61,1774,1775],"class_list":["post-1023","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cpanel","tag-cve202648172","tag-exploited","tag-litespeed","tag-plugin","tag-root","tag-run","tag-scripts"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1023"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1023\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1024"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1023"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}