logo

LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access

ID: 48a3ed85-4e8f-5f71-a654-fa14dcb846e2

STIX ID: report--48a3ed85-4e8f-5f71-a654-fa14dcb846e2

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Guru Baran

...
...

LiteSpeed disclosed and patched a critical 0‑day privilege escalation (CVE‑2026‑48172) in its cPanel user‑end plugin (affecting v2.3 through v2.4.4) that allows a cPanel user to execute arbitrary scripts as root; active exploitation has been confirmed, and operators are urged to apply cPanel plugin v2.4.5+ / WHM v5.3.1.0+ patches or uninstall the plugin, use provided log-search detection commands, and review for post‑compromise activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.