---
schema: 1
kind: vulnerability
title: "CVE-2026-48172 — LiteSpeed User-End cPanel plugin: authenticated cPanel user to root via lsws.redisAble, actively exploited"
headline: "CVE-2026-48172 — LiteSpeed User-End cPanel plugin: authenticated cPanel user to root via lsws.redisAble, actively exploited"
summary: "LiteSpeed User-End cPanel plugin CVE-2026-48172 (CVSS 4.0 = 10.0) is being actively exploited — any logged-in cPanel user can call the lsws.redisAble JSON-API endpoint to run arbitrary scripts as root on shared-hosting servers. The vendor confirms in-the-wild exploitation and ships the fix in plugin v2.4.7 / WHM v5.3.1.0 (LiteSpeed, 2026-05-21). Multi-tenant root compromise affects every co-hosted tenant on the box — patch and hunt now."
discovered_at: "2026-05-24T05:00:01Z"
event_date: 2026-05-21
run_id: 2026-05-24-f1fd8070
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - priv-esc
  - patch-available
regions:
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-48172
    cvss: "10.0"
    epss: null
    type: priv-esc
    vector: zero-click
    auth: post-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/"
    publisher: "LiteSpeed, 2026-05-21"
    role: primary
  - url: "https://github.com/advisories/GHSA-fxrh-cwjh-m33v"
    publisher: "GitHub Advisory GHSA-fxrh-cwjh-m33v, 2026-05-21"
    role: corroborating
  - url: "https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html"
    publisher: "The Hacker News, 2026-05-23"
    role: corroborating
closed_sources: []
evidence:
  - quote: "CVE-2026-48172 is an incorrect-privilege-assignment flaw (CWE-266) scored CVSS 4.0 = 10.0 in the LiteSpeed User-End cPanel plugin, versions 2.3 through 2.4.4."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch LiteSpeed cPanel plugin now if exposed** — upgrade to plugin v2.4.7 / WHM v5.3.1.0, or disable the plugin until patched; CVE-2026-48172 is actively exploited (§ 2). Hunt cPanel access logs for `cpanel_jsonapi_func=redisAble` from non-administrative accounts ([LiteSpeed, 2026-05-21](https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/))."
migrated_from: briefs/2026-05-24.md
---

CVE-2026-48172 is an incorrect-privilege-assignment flaw (CWE-266) scored CVSS 4.0 = 10.0 in the LiteSpeed User-End cPanel plugin, versions 2.3 through 2.4.4. The defect sits in the `lsws.redisAble` function of the plugin's JSON-API endpoint — the handler that toggles Redis support — which is exposed by default to every logged-in cPanel user. A single API call with crafted parameter values executes arbitrary scripts as root; there is no race to win and no administrator (WHM) access required, so any low-privilege tenant or compromised hosting account escalates to full server root ([GitHub Advisory GHSA-fxrh-cwjh-m33v, 2026-05-21](https://github.com/advisories/GHSA-fxrh-cwjh-m33v)). LiteSpeed confirms the vulnerability "is being actively exploited" across all 2.3–2.4.4 versions; cPanel auto-removed the vulnerable plugin during its 2026-05-19 nightly update, and the vendor shipped fixes in plugin v2.4.6 (initial) and v2.4.7 / WHM plugin v5.3.1.0 (full review) ([LiteSpeed, 2026-05-21](https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/)). The LiteSpeed WHM plugin is not affected.

On multi-tenant shared hosting — the dominant model for EU/CH SME and small public-sector web presences — root on the box exposes every co-tenant's TLS private keys, web-app source, database credentials and mail spool. Hunt cPanel access logs for the string `cpanel_jsonapi_func=redisAble`; any occurrence from a non-administrative account is the vendor-described exploitation artefact. Map to ATT&CK `T1068` (Exploitation for Privilege Escalation). Hardening: upgrade to plugin v2.4.7 / WHM v5.3.1.0 immediately, or disable the LiteSpeed cPanel plugin until patched.
