logo

LiteSpeed cPanel Plugin 0-Day Exploited for Server Root Access

ID: 020af072-c9ed-5ce7-a378-7363010a724d

STIX ID: report--020af072-c9ed-5ce7-a378-7363010a724d

Feed Name: GBHackers

Threat Score
95/100

Date Published: 2026-05-23

Date Updated: 2026-06-04

Author: Eswar

...
...

A critical zero-day (CVE-2026-48172) in the LiteSpeed cPanel User-End plugin enables any authenticated cPanel user to execute arbitrary commands as root and is being actively exploited; administrators should immediately run the provided IOC grep, rotate credentials if exploitation is detected, and either upgrade to the patched LiteSpeed WHM Plugin v5.3.1.0 (bundled with cPanel Plugin v2.4.7) or uninstall the vulnerable plugin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.