Ethical Hacking News
A critical vulnerability in LiteSpeed Web Server Enterprise has been discovered, which could potentially allow a low-privilege website user to gain root access on a shared-hosting server. The vulnerability, which affects versions before 6.3.7, has been described as a privilege escalation flaw, meaning that an attacker with malicious intentions could potentially exploit this vulnerability to access or alter other sites and the server itself on a shared-hosting server.
A critical vulnerability in LiteSpeed Web Server Enterprise has been discovered, allowing a low-privilege website user to gain root access on a shared-hosting server. The vulnerability, affecting versions before 6.3.7, is a privilege escalation flaw that can bypass controls keeping hosting accounts apart. cPanel has urged administrators to update to version 6.3.7, but the update process is unclear, with potential issues with automatic application. A manual update is crucial, as the stable release page still lists 6.3.6, and no matching update has been released for LiteSpeed's open-source server. cPanel's advisory does not provide workarounds for servers that cannot update at once or indicators for checking whether a server has already been attacked. This is the third time a flaw in LiteSpeed software has been reported, with previous vulnerabilities being actively exploited.
In a concerning revelation, a critical vulnerability in LiteSpeed Web Server Enterprise has been discovered, which could potentially allow a low-privilege website user to gain root access on a shared-hosting server. This alarming finding has been made public by cPanel, a prominent web hosting platform, in an advisory published on September 14, 2026.
The vulnerability, which affects versions before 6.3.7, has been described as a privilege escalation flaw, meaning that an attacker with malicious intentions could potentially exploit this vulnerability to access or alter other sites and the server itself on a shared-hosting server. According to cPanel, this type of server setup is common, with many customers' sites running on a single machine, making it an attractive target for malicious actors.
The vulnerability can bypass the controls that keep hosting accounts apart, including CageFS, a CloudLinux tool that provides each hosting account with a restricted view of the file system. This means that an attacker with one of these hosting accounts could potentially access or alter other accounts or the server's configuration files, causing significant harm to the compromised server and its users.
cPanel has urged administrators to update to version 6.3.7, which includes security improvements, bug fixes, and more. However, there is a critical issue with the update process, as LiteSpeed's release notes and the advisory do not provide clear instructions on how to install the update or whether it will be automatically applied.
LiteSpeed has released a new version, 6.3.7, with the claim of "Security improvements, bug fixes, and more!" However, its changelog only lists three security changes, without mentioning the privilege-escalation flaw. Furthermore, a check of published CVE records found no identifier or severity score for the flaw, and the advisory does not provide any information on whether the flaw has been exploited.
Both cPanel and LiteSpeed have provided the same command to install 6.3.7, which may cause issues, as 6.3.7 may not arrive on its own due to potential delays in the release process. The manual update is crucial, as LiteSpeed's download page still lists 6.3.6 as the stable release, alongside a July pre-release build of 6.4.0 (RC1), whose changelog does not mention the three security changes.
cPanel's advisory does not provide any workarounds for servers that cannot update at once, or indicators for checking whether a server has already been attacked. The advisory only names the Enterprise edition, and does not address OpenLiteSpeed, LiteSpeed's open-source server, for which LiteSpeed has released no matching update as of September 15.
This is the third time since May that a flaw in LiteSpeed software on cPanel servers has been reported to grant a hosting account root access, but the first in the web server itself. The previous vulnerabilities, CVE-2026-48172 and CVE-2026-54420, were disclosed in May and June, respectively, and were said to be actively exploited. Both vulnerabilities were fixed in the plugin, and CISA later added them to its Known Exploited Vulnerabilities catalog.
The Hacker News has contacted LiteSpeed, cPanel, and CloudLinux with questions about the flaw, but no further information has been provided. The article has also been found interesting by readers, who can follow The Hacker News on social media platforms to stay updated on the latest cybersecurity news.
Related Information:
https://www.ethicalhackingnews.com/articles/LiteSpeed-Enterprise-Flaw-Creates-Critical-Vulnerability-for-Shared-Server-Hosting-ehn.shtml
https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
Published: Tue Sep 15 04:30:57 2026 by llama3.2 3B Q4_K_M