Close Menu
NCIJ Network NCIJ Network
    What's Hot

    To understand the threat to our real democracy, watch Putin’s fake one | Rafael Behr

    September 16, 2026

    Airlines should pay for CO2 removal if Heathrow expands, say climate advisers | Climate Change Committee

    September 16, 2026

    The EOS R8 Mark II is Canon’s lightest full-frame camera with stabilization

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • To understand the threat to our real democracy, watch Putin’s fake one | Rafael Behr
    • Airlines should pay for CO2 removal if Heathrow expands, say climate advisers | Climate Change Committee
    • The EOS R8 Mark II is Canon’s lightest full-frame camera with stabilization
    • LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
    • Senate Blocks Clarity Act, Likely Killing It For 2026
    • NASA Ames Stars of the Month: September 2026
    • Latino Conservation Week Kicks Off at Threatened Arizona National Monument
    • Jeremy Greenwood denies giving ‘ridiculous’ evidence to Icac about ‘mum’s perspective’ from premier’s sister-in-law | Independent Commission Against Corruption
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 15, 2026Vulnerability / Web Security

    A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.

    On such servers, many customers’ sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory.

    cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11.

    The flaw can bypass the controls that keep hosting accounts apart, including CageFS, cPanel said. CageFS is a CloudLinux tool that gives each hosting account a restricted view of the file system, so it cannot see other accounts or the server’s configuration files.

    Cybersecurity

    Neither cPanel’s advisory nor LiteSpeed’s release notes describe how the flaw works. LiteSpeed’s announcement of 6.3.7 called it a release with “Security improvements, bug fixes, and more!” Its changelog lists three security changes but does not mention a privilege-escalation flaw, and neither company has said publicly which change fixes it.

    The advisory carries no CVE identifier or severity score, and a check of published CVE records on September 15 found none for the flaw. The advisory also does not say whether the flaw has been exploited.

    Both cPanel and LiteSpeed give the same command to install 6.3.7 now: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7

    The manual update matters because 6.3.7 may not arrive on its own: LiteSpeed said there “may be some delay” before the release reaches auto-update.

    As of September 15, LiteSpeed’s download page still listed 6.3.6 as the stable release, alongside a July pre-release build of 6.4.0 (RC1) whose changelog does not list the three security changes. cPanel’s advisory does not say whether the 6.4.0 release candidates are affected.

    LiteSpeed’s update documentation says that forcing a specific version with this command stops the server from following its stable update tier, and that administrators can resume automatic stable updates afterward by running touch /usr/local/lsws/autoupdate/follow_stable.

    Neither cPanel’s advisory nor LiteSpeed’s release notes offer a workaround for servers that cannot update at once, or indicators for checking whether a server has already been attacked. The advisory names only the Enterprise edition and does not address OpenLiteSpeed, LiteSpeed’s open-source server, for which LiteSpeed had released no matching update as of September 15.

    Cybersecurity

    It is the third time since May that a flaw in LiteSpeed software on cPanel servers has been reported to grant a hosting account root access, but the first in the web server itself.

    In May and June, LiteSpeed disclosed two such flaws in its user-end cPanel plugin, CVE-2026-48172 and CVE-2026-54420, said both were being actively exploited, and fixed both in the plugin. CISA later added both to its Known Exploited Vulnerabilities catalog, as The Hacker News reported in May and June.

    The Hacker News has contacted LiteSpeed, cPanel, and CloudLinux with questions about the flaw.

    access account enterprise Flaw gain hosting LiteSpeed Root server shared
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Acronis warns of actively exploited flaw in its cPanel backup plugin

    Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Exein Secures $270M at $1.7B Valuation for Physical AI Security

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    “We Think the Security Control Is Working” Is No Longer Good Enough

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    To understand the threat to our real democracy, watch Putin’s fake one | Rafael Behr

    September 16, 2026

    Airlines should pay for CO2 removal if Heathrow expands, say climate advisers | Climate Change Committee

    September 16, 2026

    The EOS R8 Mark II is Canon’s lightest full-frame camera with stabilization

    September 16, 2026

    LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    September 16, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    To understand the threat to our real democracy, watch Putin’s fake one | Rafael Behr

    September 16, 2026

    Airlines should pay for CO2 removal if Heathrow expands, say climate advisers | Climate Change Committee

    September 16, 2026

    The EOS R8 Mark II is Canon’s lightest full-frame camera with stabilization

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.