Vulnerability record · CVE-2026-48172 · published 21 May 2026
CVE-2026-48172: LiteSpeed cPanel Plugin Redis Feature Privilege Escalation
Litespeedtech · Litespeed Cpanel Plugin
The LiteSpeed User-End cPanel Plugin before 2.4.5 mishandles Redis enable/disable functionality, allowing privilege escalation that may reach root. It was exploited in the wild in May 2026 and is listed in CISA KEV, so unpatched cPanel/WHM hosts are at immediate risk.
Description
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score is 10.0, exploitation is confirmed in the wild, and CISA KEV lists it with a 2026-05-29 remediation due date.
What it is
The LiteSpeed User-End cPanel Plugin before 2.4.5 mishandles Redis enable/disable functionality, allowing privilege escalation that may reach root. It was exploited in the wild in May 2026 and is listed in CISA KEV, so unpatched cPanel/WHM hosts are at immediate risk.
Impact
An attacker can escalate privileges, potentially to root, gaining full control of the affected server and any hosted accounts.
Attack surface
Reachable over the network through the cPanel plugin interface with no authentication or user interaction required per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The flaw is triggered via the plugin's Redis enable/disable handling.
Exploitation
Active exploitation in the wild is confirmed by the description and CISA KEV addition on 2026-05-26; EPSS 30-day probability is 0.189 (97th percentile). No ransomware campaign use is documented.
What to do
- Upgrade the LiteSpeed cPanel/WHM plugin to version 2.4.7 or later immediately.
- If patching is not possible, disable or remove the LiteSpeed cPanel plugin until it can be updated.
- Apply vendor mitigations from the LiteSpeed advisory and follow CISA BOD 22-01 guidance for cloud services.
- Restrict network access to cPanel/WHM interfaces to trusted management networks.
- Review cPanel and WHM accounts for unexpected privilege changes after patching.
Detection
- Run grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null and investigate any matching entries.
- Examine source IP addresses in matching log entries, block invalid or untrusted ones, and review system logs for activity from those IPs.
- Monitor for unexpected Redis enable/disable actions and privilege changes in cPanel/WHM audit logs.
- Alert on plugin version below 2.4.5 across managed servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-48172 to the Known Exploited Vulnerabilities catalog on 26 May 2026 as "LiteSpeed cPanel Plugin Privilege Escalation Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 29 May 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-48172 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-48172), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.