• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
litespeed cpanel plugin cve 2026 48172 exploited to run scripts as root

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

You are here: Home / General Cyber Security News / LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
May 23, 2026

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild.

The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.

“Any cPanel user (including an attacker or a compromised account) may exploit the lsws.redisAble function to execute arbitrary scripts as root,” LiteSpeed said.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The vulnerability impacts all versions of the plugin between 2.3 and 2.4.4. LiteSpeed’s WHM plugin is not impacted. The issue has been addressed in version 2.4.5. Security researcher David Strydom has been credited with discovering and reporting the flaw.

LiteSpeed noted that the “vulnerability is being actively exploited,” but refrained from sharing additional details. It has shared the following indicator of compromise –

grep -rE “cpanel_jsonapi_func=redisAble” /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null

If running the aforementioned “grep” command does not produce any output, the server is not affected. However, if there is any output, users are advised to examine the IP addresses in the list and determine if they are legitimate, and if not, block them.

Cybersecurity

Following a security review of its cPanel and WHM plugins in the wake of the vulnerability, LiteSpeed said it has patched additional potential attack vectors in both plugins and released cPanel plugin version 2.4.7 bundled with WHM plugin version 5.3.1.0.

Users are advised to upgrade to LiteSpeed WHM Plugin version 5.3.1.0, which is bundled with cPanel plugin v2.4.7 or higher, to patch the vulnerability. If immediate patching is not an option, it’s recommended to remove the user-end plugin by running the below command –

/usr/local/lsws/admin/misc/lscmctl cpanelplugin –uninstall

The development comes weeks after a critical cPanel vulnerability (CVE-2026-41940, CVSS score: 9.8) was identified as actively exploited by unknown threat actors to deploy Mirai botnet variants and a ransomware strain called Sorry.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «drupal core sql injection bug actively exploited, added to cisa Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
  • Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
  • First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
  • Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
  • Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
  • Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective
  • Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks
  • CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
  • Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
  • Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Copyright © TheCyberSecurity.News, All Rights Reserved.