VMTech
Discuss a project

LiteSpeed Enterprise Bug Risks Root Access on Shared Hosting

LiteSpeed Enterprise Bug Risks Root Access on Shared Hosting

cPanel urges LiteSpeed Enterprise 6.3.7 update

cPanel has warned of a critical vulnerability in LiteSpeed Web Server Enterprise that could allow a low-privilege website user to gain root access on a shared-hosting server. The issue affects releases before version 6.3.7, which LiteSpeed published on September 11.

On a shared server, numerous customers’ sites run on the same machine. An attacker controlling one hosting account could use the flaw to access or alter other sites and the server itself, cPanel said in its September 14 advisory.

Administrators are being urged to install version 6.3.7 directly with /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. Both cPanel and LiteSpeed provided that command as the immediate update path.

Isolation controls may be bypassed

cPanel said the vulnerability can bypass controls intended to separate hosting accounts, including CageFS. The CloudLinux tool gives each hosting account a restricted view of the file system, limiting access to other accounts and to server configuration files.

Neither cPanel’s advisory nor LiteSpeed’s release notes explain the technical mechanism behind the flaw. LiteSpeed described 6.3.7 as a release containing security improvements and bug fixes, while its changelog lists three security changes without identifying a privilege-escalation issue.

There is no CVE identifier, severity score, or public confirmation of exploitation. The advisory also provides no workaround for installations that cannot update immediately and no indicators to help administrators determine whether a server has already been compromised.

Manual action may be required

The update may not arrive through the normal channel promptly. LiteSpeed said there may be a delay before 6.3.7 reaches auto-update, and its download page still listed 6.3.6 as the stable release on September 15. A July 6.4.0 RC1 release did not list the same three security changes, and cPanel did not state whether release candidates are affected.

LiteSpeed documentation says forcing a version stops the server from following its stable update tier. After validating the upgrade, administrators can resume automatic stable updates with touch /usr/local/lsws/autoupdate/follow_stable.

The advisory names LiteSpeed Enterprise only and does not address OpenLiteSpeed. This is the third reported root-access issue affecting LiteSpeed software on cPanel servers since May, following actively exploited flaws in the user-end cPanel plugin, CVE-2026-48172 and CVE-2026-54420. For businesses operating shared hosting, the practical priority is to identify Enterprise installations, apply 6.3.7 as soon as change controls permit, and track systems that remain exposed.

#cybersecurity#sharedhosting#litespeed#vulnerability
Open analytics
On the site 0 views
min read 3 15.09.2026
Instagram

LiteSpeed Enterprise Bug Risks Root Access on Shared Hosting

Open the post on Instagram ↗