Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Shared Hosting at Risk: A Critical Vulnerability in LiteSpeed Enterprise Could Grant Root Access to a Single Tenant




A critical vulnerability in LiteSpeed Enterprise, a web server software used on shared hosting servers, could grant root access to a single tenant, compromising the security of dozens or hundreds of customers. To mitigate this risk, admins are urged to update to version 6.3.7, but the company warns that the process may take time. This vulnerability is the latest in a series of critical issues affecting LiteSpeed-related flaws, highlighting the importance of keeping software up-to-date and taking proactive steps to protect against emerging threats.

  • A critical privilege-escalation vulnerability has been identified in LiteSpeed Enterprise, allowing a low-privilege user to gain root-level access to the server.
  • The vulnerability affects versions before 6.3.7 and can bypass isolation restrictions.
  • Admins are urged to update their installs with the command /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7.
  • Version 6.3.7 may take some time to reach the stable auto-update channel.
  • This vulnerability is part of a series of critical issues affecting LiteSpeed-related flaws.



  • A recent vulnerability discovered in LiteSpeed Enterprise, a web server software used on shared hosting servers, poses a significant risk to the security of these platforms. According to an advisory from cPanel, a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise, allowing a low-privilege website user to gain root-level access to the server. This could enable an attacker to access or modify other hosted websites and the server itself, compromising the security of dozens or hundreds of customers living side by side on a single box.

    The vulnerability affects versions before 6.3.7 and can bypass the isolation that keeps hosting accounts apart, including CageFS, a CloudLinux layer that restricts a user's view of the filesystem. This means that a malicious website user could potentially escape its restricted environment and gain root-level access to the server. Neither cPanel nor LiteSpeed has disclosed the technical details of the vulnerability, but the company's September 11 announcement for version 6.3.7 mentions only "Security improvements, bug fixes, and more!"

    To mitigate this risk, admins are urged to run a specific command to update their installs: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. However, LiteSpeed warns that version 6.3.7 may take some time to reach the stable auto-update channel, and there is no workaround for systems that cannot be patched immediately. The advisory only covers the Enterprise edition, while the open-source variant, OpenLiteSpeed, has no matching update as of September 15.

    This vulnerability is the latest in a series of critical issues affecting LiteSpeed-related flaws, which have now been linked to three root-level escapes on cPanel shared-hosting servers since May. In this year, LiteSpeed fixed two flaws in its cPanel plugin, CVE-2026-48172 and CVE-2026-54420, which were being actively exploited in the wild. CISA added both issues to its Known Exploited Vulnerabilities catalog.

    The discovery of this vulnerability highlights the importance of keeping software up-to-date and the need for robust security measures in place. As the threat landscape continues to evolve, it is essential for users to stay informed and take proactive steps to protect themselves against emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Shared-Hosting-at-Risk-A-Critical-Vulnerability-in-LiteSpeed-Enterprise-Could-Grant-Root-Access-to-a-Single-Tenant-ehn.shtml

  • https://securityaffairs.com/199127/security/shared-hosting-at-risk-litespeed-enterprise-bug-can-grant-root-from-a-single-tenant.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-54420

  • https://www.cvedetails.com/cve/CVE-2026-54420/


  • Published: Tue Sep 15 09:22:42 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us