A critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privilege website user to gain root access on a shared-hosting server, according to a security advisory from cPanel published on September 14.
The issue is particularly serious for shared-hosting environments, where multiple customers’ websites operate on the same server. An attacker who controls one hosting account could potentially use the vulnerability to bypass account isolation and access or modify other customers’ websites and server resources.
cPanel said the vulnerability affects LiteSpeed Web Server Enterprise versions earlier than 6.3.7 and urged administrators to upgrade. LiteSpeed released version 6.3.7 on September 11 with security improvements and bug fixes.
The flaw can bypass security controls designed to isolate hosting accounts, including CageFS, a CloudLinux technology that provides each account with a restricted view of the server’s filesystem. This prevents users from accessing other accounts and sensitive server configuration files.
Neither cPanel nor LiteSpeed has publicly explained how the vulnerability works. LiteSpeed’s release announcement describes version 6.3.7 as containing “Security improvements, bug fixes, and more,” while its changelog lists three security-related changes without identifying a privilege-escalation vulnerability. The companies have also not confirmed which specific change addresses the issue.
The vulnerability currently has no CVE identifier or public severity score. A review of published CVE records on September 15 did not identify a matching entry. The cPanel advisory also does not say whether attackers have exploited the vulnerability in the wild.
Administrators can manually install LiteSpeed Web Server Enterprise 6.3.7 using the following command:
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7A manual update is recommended because LiteSpeed warned that there could be a delay before version 6.3.7 becomes available through automatic updates.
As of September 15, LiteSpeed’s download page continued to list version 6.3.6 as the stable release, while a July pre-release version of 6.4.0 was available as Release Candidate 1. Its changelog does not list the three security changes included in 6.3.7, and cPanel has not clarified whether the 6.4.0 release candidates are affected.
LiteSpeed’s documentation also warns that forcing a specific version can stop the server from following its normal stable update tier. Administrators who want to return to automatic stable updates can run:
touch /usr/local/lsws/autoupdate/follow_stableThere is currently no workaround provided by cPanel or LiteSpeed for servers that cannot immediately install the update. The advisories also do not provide indicators of compromise that administrators can use to determine whether the vulnerability has already been abused.
The issue specifically affects LiteSpeed Web Server Enterprise. Neither cPanel nor LiteSpeed has indicated that OpenLiteSpeed, the open-source version of the server, is affected, and no corresponding update had been released for OpenLiteSpeed as of September 15.
This is the third LiteSpeed-related vulnerability reported since May that could allow a hosting account to obtain root-level access on cPanel servers. However, this is the first of the three flaws found directly in the LiteSpeed web server itself.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Earlier vulnerabilities affected the LiteSpeed cPanel plugin. CVE-2026-48172 and CVE-2026-54420 were disclosed in May and June, respectively, and LiteSpeed said both were being actively exploited. Both vulnerabilities were subsequently fixed, with CISA later adding them to its Known Exploited Vulnerabilities catalog.



