Vulnerabilities

CVE-2026-48172

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

Actively exploited (CISA KEV) Critical 9.8 CVSS 3.1

Description

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

Description as published by the source, in English.

Key facts

Published
2026-05-21
Last modified
2026-07-23
Assigned by
cve@mitre.org
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored by
nvd@nist.gov (NVD Primary)
Probability of exploitation
18.9 % higher than 97 % of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Not registered in the sources

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-26, with a remediation deadline of 2026-05-29 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Litespeedtech Litespeed Cpanel Plugin < 2.4.7 Affected
Litespeedtech Litespeed Whm Plugin < 5.3.1.0 Affected

Weakness type

References

Related at Berigo

Articles

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities