CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW)

cve · CVE-2026-48172

Coverage
1
first 2026-05-24 → last 2026-05-31
Latest activity
2026-05-24
CVE-2026-48172, LiteSpeed User-End cPanel plugin: authenticated cPanel user to root via lsws.redisAble…
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
3
3 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-48172, newest first. Check the date before acting on an older one.

  • Patch LiteSpeed cPanel plugin now if exposed, upgrade to plugin v2.4.7 / WHM v5.3.1.0, or disable the plugin until patched; CVE-2026-48172 is actively exploited (§ 2). Hunt cPanel access logs for cpanel_jsonapi_func=redisAble from non-administrative accounts (LiteSpeed, 2026-05-21).
    2026-05-24CVE-2026-48172

Story timeline

  1. 2026-05-24CVE-2026-48172, LiteSpeed User-End cPanel plugin: authenticated cPanel user to root via lsws.redisAble, actively exploited
    trending-vulnerabilities
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Privilege EscalationExploitation for Privilege Escalation

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-05-24/cve-2026-48172-litespeed-user-end-cpanel-plugin-authenticate · ATT&CK page ↗

Entries about LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW) (1)

2026-05-24 · view entry permalink →

HIGHCVE-2026-48172exploited

CVE-2026-48172, LiteSpeed User-End cPanel plugin: authenticated cPanel user to root via lsws.redisAble, actively exploited

CVE-2026-48172 is an incorrect-privilege-assignment flaw (CWE-266) scored CVSS 4.0 = 10.0 in the LiteSpeed User-End cPanel plugin, versions 2.3 through 2.4.4. The defect sits in the lsws.redisAble function of the plugin's JSON-API endpoint (the handler that toggles Redis support) which is exposed by default to every logged-in cPanel user. A single API call with crafted parameter values executes arbitrary scripts as root; there is no race to win and no administrator (WHM) access required, so any low-privilege tenant or compromised hosting account escalates to full server root (GitHub Advisory GHSA-fxrh-cwjh-m33v, 2026-05-21). LiteSpeed confirms the vulnerability "is being actively exploited" across all 2.3–2.4.4 versions; cPanel auto-removed the vulnerable plugin during its 2026-05-19 nightly update, and the vendor shipped fixes in plugin v2.4.6 (initial) and v2.4.7 / WHM plugin v5.3.1.0 (full review) (LiteSpeed, 2026-05-21). The LiteSpeed WHM plugin is not affected.

On multi-tenant shared hosting (the dominant model for EU/CH SME and small public-sector web presences) root on the box exposes every co-tenant's TLS private keys, web-app source, database credentials and mail spool. Hunt cPanel access logs for the string cpanel_jsonapi_func=redisAble; any occurrence from a non-administrative account is the vendor-described exploitation artefact. Map to ATT&CK T1068 (Exploitation for Privilege Escalation). Hardening: upgrade to plugin v2.4.7 / WHM v5.3.1.0 immediately, or disable the LiteSpeed cPanel plugin until patched.

CVE-2026-48172 is an incorrect-privilege-assignment flaw (CWE-266) scored CVSS 4.0 = 10.0 in the LiteSpeed User-End cPanel plugin, versions 2.3 through 2.4.4.

ctipilot v2 brief (migrated)
vulnerability24 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Vulns1

Source distribution

  • blog.litespeedtech.com1 (33%)
  • github.com1 (33%)
  • thehackernews.com1 (33%)