Skip to content

Security1 publisher2 min readPublished

cPanel warns a single hosting account can take root on unpatched LiteSpeed Enterprise servers

cPanel's September 14 advisory covers every LiteSpeed Web Server Enterprise build before 6.3.7. The fix shipped on September 11; because auto-update may lag, administrators have to force it onto servers by hand.

The Watch · Security desk

Illustration accompanying cPanel warns a single hosting account can take root on unpatched LiteSpeed Enterprise servers

What happened

  • cPanel published an advisory on September 14 saying a low-privilege website user on a shared server running LiteSpeed Web Server Enterprise could gain root access on that machine.
  • The flaw bypasses the controls that keep hosting accounts apart, including CloudLinux's CageFS, which normally limits each account to a restricted view of the file system.
  • LiteSpeed published the fixed release, 6.3.7, on September 11; every earlier Enterprise build is affected, and cPanel told administrators to update to it.
  • cPanel did not assign a CVE identifier or severity score, or say whether the flaw has been exploited; a check of published CVE records on September 15 turned up no entry.
  • This is the third LiteSpeed root-escalation flaw reported on cPanel servers since May, and the first one in the web server rather than in LiteSpeed's cPanel plugin.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure On an unpatched machine the separation customers are paying for is what fails: one hosting account becomes a route to every other site on the box and to the server's own configuration.
  • constraint Patching now pins the server to 6.3.7 and takes it off its stable update tier, so whoever runs the emergency update also owns the follow-up job of switching automatic updates back on.
  • decision No workaround has been published and there are no indicators to hunt against, so an operator who cannot take an immediate update window is choosing between running exposed and taking customer sites down.
  • precedent Shipping a root-escalation fix inside an unattributed changelog, with no identifier attached, sets the terms for the next one: fleet-wide forced installs with nothing to triage against.

The 6.3.7 changelog lists three security changes, and neither cPanel nor LiteSpeed has said which one closes the root path [8]. LiteSpeed's announcement of the release described it as a build with "Security improvements, bug fixes, and more!" [7]. cPanel's advisory does not describe how the flaw works [6]. That leaves an administrator one step: the install.

Three days separated the fix and the advisory [1]. The update may not arrive on its own: LiteSpeed said there "may be some delay" before the release reaches auto-update [12], and both companies publish the same forced-version command, /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 [11]. Four days after 6.3.7 shipped, LiteSpeed's own download page still listed 6.3.6 as the stable release [2].

That command has a side effect. LiteSpeed's update documentation says forcing a specific version stops the server following its stable update tier, and that automatic stable updates resume after running touch /usr/local/lsws/autoupdate/follow_stable [15]. A fleet patched in a hurry and never un-pinned sits on 6.3.7 and does not pick up later stable builds.

The advisory covers the Enterprise edition only. It leaves out OpenLiteSpeed, the open-source server, and LiteSpeed had released no matching update for it as of September 15 [17]. The July release candidate for 6.4.0 sits outside the advisory too: its changelog omits the three security changes, and cPanel is silent on whether the release candidates are affected [13][14].

The two earlier root paths were both in LiteSpeed's user-end cPanel plugin. LiteSpeed disclosed CVE-2026-48172 in May and CVE-2026-54420 in June, said both were being actively exploited, and fixed both in the plugin; CISA later added both to its Known Exploited Vulnerabilities catalog [19]. This one is in the web server that answers the requests [18]. The Hacker News said it has contacted LiteSpeed, cPanel and CloudLinux with questions about the flaw [20].

What to watch

  • A CVE assignment or a KEV entry for this flaw, either of which would put a dated deadline on the update.
  • Whether LiteSpeed promotes 6.3.7 to stable on its download page, removing the need for the forced install.
  • Any statement from LiteSpeed on whether the 6.4.0 release candidates and OpenLiteSpeed share the affected code.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories