LiteSpeed Enterprise Flaw Grants Root Access on Shared Servers
A critical vulnerability in LiteSpeed Web Server Enterprise allows low-privilege users to escalate to root access on shared hosting environments, potentially compromising other websites on the same server.

A critical vulnerability has been discovered in LiteSpeed Web Server Enterprise that could allow a user with minimal privileges on a shared hosting server to gain full root access. This significant security flaw, detailed in an advisory by cPanel on September 14, 2026, poses a substantial risk to the integrity and confidentiality of multiple websites hosted on a single machine.
Shared hosting environments are designed with isolation mechanisms to prevent one customer's account from affecting others or the underlying server infrastructure. However, this newly disclosed vulnerability bypasses these protections, including CloudLinux's CageFS, which is intended to provide each hosting account with a restricted view of the file system. An attacker exploiting this flaw could potentially access, modify, or delete data belonging to other hosted websites and gain control over the server itself.
The vulnerability affects versions of LiteSpeed Web Server Enterprise prior to 6.3.7. LiteSpeed released version 6.3.7 on September 11, 2026, with an advisory urging administrators to update immediately. While neither cPanel nor LiteSpeed has publicly disclosed the specific technical details of how the flaw is exploited, LiteSpeed's release notes for version 6.3.7 mention "Security improvements, bug fixes, and more!" and list three security-related changes, one of which is presumed to address this privilege escalation issue.
As of September 15, 2026, the advisory lacked a CVE identifier or a CVSS severity score, and no public CVE record for this specific flaw had been found. Furthermore, there was no information available regarding whether the vulnerability had been actively exploited in the wild. This lack of immediate detail underscores the urgency for administrators to apply the patch without delay.
To update to the patched version, administrators are instructed to run the command /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. LiteSpeed noted that there might be a delay before version 6.3.7 becomes available through automatic updates, making manual intervention necessary for prompt protection. After forcing the update to a specific version, administrators can re-enable automatic stable updates by running touch /usr/local/lsws/autoupdate/follow_stable.
No specific workarounds were provided by either cPanel or LiteSpeed for environments unable to update immediately, nor were there any indicators to help detect if a server had already been compromised. The advisory specifically named the Enterprise edition of LiteSpeed Web Server, and it remains unclear if the open-source OpenLiteSpeed version is affected or if a corresponding patch is available.
This incident marks the third time since May 2026 that a vulnerability in LiteSpeed software used on cPanel servers has allowed hosting account users to gain root access. Previously, two flaws in LiteSpeed's cPanel plugin (CVE-2026-48172 and CVE-2026-54420) were disclosed, confirmed to be actively exploited, and subsequently patched. Both of those plugin vulnerabilities were later added to CISA's Known Exploited Vulnerabilities catalog, highlighting a recurring pattern of privilege escalation risks within the LiteSpeed ecosystem on cPanel platforms.
Security researchers and administrators are advised to monitor for further technical disclosures from LiteSpeed and cPanel regarding this vulnerability and to ensure all LiteSpeed Web Server Enterprise installations are updated to version 6.3.7 to mitigate the risk of unauthorized root access and potential compromise of hosted websites.