LiteSpeed cPanel Plugin Flaw Hands Root to Any Logged-In User, and the Vendor Won't Say How Many Hosts Are Hit
CVE-2026-48172 carries a CVSS of 10.0, is already being exploited, and LiteSpeed has not answered three questions about exploitation telemetry.

A privilege-assignment bug in the LiteSpeed User-End cPanel Plugin is being exploited in the wild to run arbitrary scripts as root on shared hosting servers. The flaw, CVE-2026-48172, scores a maximum 10.0 on CVSSv3. Any authenticated cPanel user, including a low-privilege account purchased on a reseller plan or one taken over through a stolen password, can use the plugin path to execute code with full system privileges.
That is the technical summary. Now the questions LiteSpeed Technologies has not answered.
I emailed the company's press contact three times between the disclosure and this story going live. Each message asked the same three things: how many servers run the affected plugin, when LiteSpeed first received exploitation reports, and whether the fixed build is being pushed automatically or only offered as an update. No response. The vendor's public advisory does not give numbers either. (LiteSpeed's own marketing pages claim the plugin is bundled with "millions" of cPanel accounts. The advisory does not repeat that figure.)
The vulnerability is in how the plugin assigns privileges when a cPanel user invokes one of its endpoints. The plugin runs server-side actions as root by design, to manage cache files outside a user's home directory. The bug is that it does not adequately gate which scripts a calling user may trigger. So a $4-a-month shared hosting account becomes a root shell.
That is not a theoretical escalation path. Shared hosting is the natural habitat of credential-stuffed cPanel logins, and the plugin ships enabled by default on LiteSpeed Web Server and OpenLiteSpeed installations that opted into the cPanel integration.
LiteSpeed's advisory tells administrators to update to the latest plugin build. It does not name a CVE-fixed version in the body of the public bulletin I reviewed, which makes verification harder for downstream hosting providers trying to confirm whether their fleet is patched. Asked to clarify the exact fixed build string, the company did not reply.
CISA has not yet added CVE-2026-48172 to the Known Exploited Vulnerabilities catalog as of this writing. A spokesperson for the agency declined to say whether a review is underway, citing policy on pending entries.
And the hosts? The real population at risk is not LiteSpeed's direct customers. It is the resellers who sell cPanel accounts on top of LiteSpeed servers, many of whom do not know which plugins their upstream provider has enabled. None of the three large reseller networks I contacted, NameHero, Hostinger, and A2 Hosting, returned a request for comment on whether they had completed patching.
Who is exploiting this, and since when? LiteSpeed has not said. Neither has anyone else, on the record.



