LiteSpeed Web Server Enterprise: critical privilege escalation to root on shared hosts (fix 6.3.7)
cPanel Security advisory (14 September 2026) warns of a critical privilege-escalation flaw in LiteSpeed Web Server Enterprise: on shared-hosting servers a malicious low-privilege website user could gain root-level access, bypassing account isolation including CageFS, and access or alter other sites and the server. Affected: LiteSpeed Web Server Enterprise prior to v6.3.7. Fix: upgrade to 6.3.7 or later. cPanel/LiteSpeed publish the forced update command /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 (auto-update may lag; as of THN 15 Sep, download page still listed 6.3.6 as stable). LiteSpeed store announcement for 6.3.7 (11 September 2026) lists three security changes (lscgid auth, internal redirect URL validation, block internal-use env vars from .htaccess) without naming a CVE or privilege-escalation root cause; neither cPanel nor LiteSpeed assigned a public CVE or CVSS for this Enterprise web-server issue as of 15 September 2026 desk check. Advisory does not state in-the-wild exploitation for this Enterprise flaw (distinct from earlier actively exploited LiteSpeed cPanel-plugin issues CVE-2026-48172 and CVE-2026-54420 already on this desk). OpenLiteSpeed not named in the cPanel advisory. Primary: cPanel; vendor release: LiteSpeed 6.3.7 announcement; wire: The Hacker News (15 Sep 2026).
- Product
- LiteSpeed Web Server Enterprise (shared hosting / cPanel stacks; CageFS isolation)
- Versions
- Enterprise prior to 6.3.7; fixed in 6.3.7+
- Exploited in Australia?
- unknown
- Patch to
- Force-upgrade LiteSpeed Enterprise to 6.3.7+ via /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7; resume follow_stable afterward per LiteSpeed docs; no vendor workaround published
Primary: cPanel — LiteSpeed Enterprise security advisory (14 Sep 2026) · Vendor: LiteSpeed — Web Server v6.3.7 announcement (11 Sep 2026) · CVE: CVE-2026-48172, CVE-2026-54420 · The Hacker News (15 Sep 2026)
