Critical alert: CVE-2026-48172 allows you to run scripts as root in LiteSpeed User-End for cPanel; recommended immediate patch

Author: Published 3 min de lectura 202 reading

The images in this article were generated with artificial intelligence. How we publish

A vulnerability of maximum severity has been reported and confirmed as being exploited in real environments in the LiteSpeed User-End plugin for cPanel: CVE-2026-48172(CVSS 10.0). According to the manufacturer, the failure consists of an incorrect allocation of privileges that allows any cPanel user - including an attacker with a compromised account - to invoke the lsws.redisAble function for run arbitrary scripts with root permissions. The problem affects the plugin versions between 2.3 and 2.4.4; the correction is available from version 2.4.5 and LiteSpeed has published more later patches integrated into the recommended package.

The active operating presence increases the immediate risk for shared hosting servers, VPS and any infrastructure using the affected plugin, because the execution as root allows an attacker to install persistent back doors, deploy botnets, miners or ransomware, or take full control of the node. This incident comes weeks after another critical vulnerability in the cPanel ecosystem that was used to distribute Mirai and Ransomware variants, which highlights the ease with which management component failures can become powerful attack vectors.

Critical alert: CVE-2026-48172 allows you to run scripts as root in LiteSpeed User-End for cPanel; recommended immediate patch
Image generated with IA.

As urgent measures, and always prioritizing the minimum possible exposure, update immediately to the version of plugin cPanel 2.4.7 and to the plugin WHM 5.3.1.0 or higher as recommended by the supplier. If it is not possible to apply the patch immediately, LiteSpeed proposes to temporarily remove the user plugin; check the official instructions and, before running drastic changes, coordinate with your hosting provider or the operations team to avoid unexpected interruptions. In all cases, contact the LiteSpeed support to receive the commitment indicators (IOC) and the check commands they have published.

In addition to patching or removing the vulnerable component, an incident investigation is essential: search processes and scripts running as root that does not recognize, new or modified crons, unexpected user accounts, webshells and outgoing connections to IPs or unknown domains. Check the Apache / Nginx, cPanel / WHM and authentication records to detect abnormal accesses; rote credentials and keys that may have been compromised and, in the light of the slightest suspicion of commitment, isolate the server and restore it from a validated clean backup.

Critical alert: CVE-2026-48172 allows you to run scripts as root in LiteSpeed User-End for cPanel; recommended immediate patch
Image generated with IA.

To minimize the attack surface while applying the remediation, consider applying containment controls: restrict access to cPanel / WHM by IP, strengthen password policies and multifactor authentication, monitor outgoing processes and connections with EDR / NDR tools and maintain unmuted copies of backups. These practices reduce the probability of scaling and spreading from a compromised user account to total system control.

LiteSpeed has accredited researcher David Strydom for the finding and has indicated that, following the incident, additional vectors have been patched in both plugins. For official information and updates, see the manufacturer's security centre and the documentation of the hosting ecosystem. You can start at LiteSpeed security center and review cPanel general ads and recommendations on your official blog: CPanel Blog. For good practice in response and mitigation of intrusions, the OWASP community reference guide may be useful: OWASP.

In summary: try CVE-2026-48172 as a critical priority: park or remove the vulnerable plugin now, investigate any sign of commitment urgently and apply containment controls while strengthening the security position of your hosting environment. If you manage or provide hosting services, tell your customers about the risk and actions taken to contain it.

Coverage

Related

More news on the same subject.