Cyber Security News

cPanel LiteSpeed Web Server Vulnerability Allows Shared Server Users to Gain Root-Level Access

cPanel has issued an urgent security advisory warning that a critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privileged shared-hosting user to gain root-level access to an affected server. Administrators are urged to upgrade LiteSpeed Enterprise to version 6.3.7 or later immediately.

The flaw affects LiteSpeed Web Server Enterprise versions earlier than 6.3.7. It is particularly serious for shared-hosting environments, where many separate customer websites and user accounts run on the same physical or virtual server.

According to the advisory, a malicious user with access to a low-privilege website account may be able to escalate privileges and obtain root-level control of the server. Root access is the highest privilege level on Linux systems.

It can allow an attacker to modify system settings, access hosted files, install malware, change configurations, and create persistent backdoors.

The vulnerability may also let attackers bypass expected isolation mechanisms designed to separate hosting accounts. cPanel specifically noted that the issue could bypass controls.

cPanel LiteSpeed Web Server Vulnerability

One of them is CageFS, a CloudLinux security feature that restricts users to their own virtualized filesystem environment. In a normal shared-hosting setup, CageFS helps prevent one customer from viewing or modifying files belonging to another customer.

If an attacker escapes that restricted environment and gains root privileges, they could access other hosted websites, steal databases and credentials, alter web content, deploy phishing pages, or compromise the underlying server.

The risk is significant because shared-hosting platforms commonly host dozens, hundreds, or even thousands of websites. A single compromised low-privilege account could therefore become an entry point for a broader server-wide incident.

cPanel said it received notice of the critical privilege-escalation issue and recommends updating all affected LiteSpeed Enterprise deployments without delay.

The company identified LiteSpeed Web Server Enterprise version 6.3.7 as the fixed release. Administrators can update LiteSpeed using the following command: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7.

Server operators should verify the installed LiteSpeed version before and after patching, review privileged account activity, and investigate unusual changes in website directories, web server configuration files, cron jobs, SSH keys, or system binaries.

Hosting providers should also monitor for suspicious behavior originating from customer accounts, especially attempts to access restricted filesystem paths or execute commands outside normal web application processes.

Organizations running LiteSpeed Enterprise on cPanel-based shared servers should treat the update as a high-priority maintenance task.

Because the vulnerability can undermine tenant isolation and lead to root-level compromise, delaying remediation may expose every website hosted on an affected server to potential unauthorized access or modification.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago