{"id":2859,"date":"2026-09-15T08:49:31","date_gmt":"2026-09-15T08:49:31","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2859"},"modified":"2026-09-15T08:49:31","modified_gmt":"2026-09-15T08:49:31","slug":"litespeed-enterprise-flaw-could-let-one-hosting-account-gain-root-access-on-a-shared-server","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2859","title":{"rendered":"LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 15, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjRVzSne-2lfRX57xj9CbnkpX1fjEWXYoPN0tDsXwgBwaE_LVqYBKtWbO1nudNLKp89aR90EeszJUqsNvZN4ZLzU1i7hm89ihV-lK1mIKiNXl6GWAWkn6uz7WlRVfIdJrS7Nfn6x-1Cclf6oTs3RxVNWxQSVBsvhzDjMBnmU3l3oERVu3b5hqag5mSeKoU\/s1700-nu-rw-lo-l85-e365\/litespeed.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A critical vulnerability in <strong>LiteSpeed Web Server Enterprise<\/strong> could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026\" target=\"_blank\">advisory published on September 14<\/a>.<\/p>\n<p>On such servers, many customers&#8217; sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory.<\/p>\n<p>cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed <a href=\"https:\/\/store.litespeedtech.com\/store\/index.php?rp=\/announcements\/895\/LiteSpeed-Web-Server-v6.3.7-Now-Available.html\" target=\"_blank\">published on September 11<\/a>.<\/p>\n<p>The flaw can bypass the controls that keep hosting accounts apart, including <a href=\"https:\/\/docs.cloudlinux.com\/cloudlinuxos\/cloudlinux_os_components\/#cagefs\" target=\"_blank\">CageFS<\/a>, cPanel said. CageFS is a CloudLinux tool that gives each hosting account a restricted view of the file system, so it cannot see other accounts or the server&#8217;s configuration files.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Neither cPanel&#8217;s advisory nor LiteSpeed&#8217;s release notes describe how the flaw works. LiteSpeed&#8217;s announcement of 6.3.7 called it a release with \u00abSecurity improvements, bug fixes, and more!\u00bb Its <a href=\"https:\/\/docs.litespeedtech.com\/lsws\/changelog\/\" target=\"_blank\">changelog<\/a> lists three security changes but does not mention a privilege-escalation flaw, and neither company has said publicly which change fixes it.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The advisory carries no CVE identifier or severity score, and a check of published CVE records on September 15 found none for the flaw. The advisory also does not say whether the flaw has been exploited.<\/p>\n<p>Both cPanel and LiteSpeed give the same command to install 6.3.7 now: \/usr\/local\/lsws\/admin\/misc\/lsup.sh -f -v 6.3.7<\/p>\n<p>The manual update matters because 6.3.7 may not arrive on its own: LiteSpeed said there \u00abmay be some delay\u00bb before the release reaches auto-update.<\/p>\n<p>As of September 15, LiteSpeed&#8217;s <a href=\"https:\/\/www.litespeedtech.com\/products\/litespeed-web-server\/download\" target=\"_blank\">download page<\/a> still listed 6.3.6 as the stable release, alongside a July pre-release build of 6.4.0 (RC1) whose changelog does not list the three security changes. cPanel&#8217;s advisory does not say whether the 6.4.0 release candidates are affected.<\/p>\n<p>LiteSpeed&#8217;s <a href=\"https:\/\/docs.litespeedtech.com\/lsws\/updates\/\" target=\"_blank\">update documentation<\/a> says that forcing a specific version with this command stops the server from following its stable update tier, and that administrators can resume automatic stable updates afterward by running touch \/usr\/local\/lsws\/autoupdate\/follow_stable.<\/p>\n<p>Neither cPanel&#8217;s advisory nor LiteSpeed&#8217;s release notes offer a workaround for servers that cannot update at once, or indicators for checking whether a server has already been attacked. The advisory names only the Enterprise edition and does not address OpenLiteSpeed, LiteSpeed&#8217;s open-source server, for which LiteSpeed had released no matching update as of September 15.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It is the third time since May that a flaw in LiteSpeed software on cPanel servers has been reported to grant a hosting account root access, but the first in the web server itself.<\/p>\n<p>In May and June, LiteSpeed disclosed two such flaws in its user-end cPanel plugin, <a href=\"https:\/\/blog.litespeedtech.com\/2026\/05\/21\/security-update-for-litespeed-cpanel-plugin\/\" target=\"_blank\">CVE-2026-48172<\/a> and <a href=\"https:\/\/blog.litespeedtech.com\/2026\/06\/01\/security-update-for-litespeed-cpanel-plugin-2\/\" target=\"_blank\">CVE-2026-54420<\/a>, said both were being actively exploited, and fixed both in the plugin. CISA later added both to its Known Exploited Vulnerabilities catalog, as The Hacker News reported in May and June.<\/p>\n<p>The Hacker News has contacted LiteSpeed, cPanel, and CloudLinux with questions about the flaw.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Sep 15, 2026Vulnerability \/ Web Security A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2860,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,573,587,70,580,2869,1772,61,518,1527],"class_list":["post-2859","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-account","tag-enterprise","tag-flaw","tag-gain","tag-hosting","tag-litespeed","tag-root","tag-server","tag-shared"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2859"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2859\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2860"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}