CPANEL has warned that a critical, undisclosed vulnerability in LiteSpeed Web Server Enterprise could allow a low-privilege user on a shared-hosting server to escape their account and gain root-level access. The flaw can bypass account-isolation controls, including CloudLinux’s CageFS, potentially allowing an attacker to access or alter other customers’ websites and the server itself.
The issue affects versions before 6.3.7. cPanel and LiteSpeed have not published technical details, a CVE or a severity rating, and there is no confirmation that the vulnerability is being exploited.
Administrators are urged to update to LiteSpeed Enterprise 6.3.7 using `/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7`. LiteSpeed said the release might take time to enter the stable automatic-update channel; on 15 September 2026, its download page still listed 6.3.6 as the latest stable version. The article says there is no workaround for systems that cannot be patched immediately. The advisory applies to the Enterprise edition only, with no corresponding OpenLiteSpeed update reported by that date.
The incident follows two other LiteSpeed cPanel plugin vulnerabilities, CVE-2026-48172 and CVE-2026-54420, which the article says were actively exploited and added by CISA to its Known Exploited Vulnerabilities catalogue.