CVE-2026-48172

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:*

History

26 May 2026, 20:19

Type Values Removed Values Added
References () https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ - () https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ - Vendor Advisory
References () https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel - () https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel - Product
References () https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log - () https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log - Release Notes
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48172 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48172 - US Government Resource
CPE cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Litespeedtech litespeed Cpanel Plugin
Litespeedtech
Litespeedtech litespeed Whm Plugin

26 May 2026, 19:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48172 -
References () https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ - () https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ -

22 May 2026, 20:16

Type Values Removed Values Added
References
  • () https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ -

21 May 2026, 18:16

Type Values Removed Values Added
Summary (en) LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. LiteSpeed WHM Plugin (the parent plugin) is unaffected. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. (en) LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

21 May 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 02:16

Updated : 2026-05-26 20:19


NVD link : CVE-2026-48172

Mitre link : CVE-2026-48172

CVE.ORG link : CVE-2026-48172


JSON object : View

Products Affected

litespeedtech

  • litespeed_cpanel_plugin
  • litespeed_whm_plugin
CWE
CWE-266

Incorrect Privilege Assignment