← Vulnerability feed

Vulnerability record · CVE-2026-48172 · published 21 May 2026

CVE-2026-48172: LiteSpeed cPanel Plugin Redis Feature Privilege Escalation

Litespeedtech · Litespeed Cpanel Plugin

The LiteSpeed User-End cPanel Plugin before 2.4.5 mishandles Redis enable/disable functionality, allowing privilege escalation that may reach root. It was exploited in the wild in May 2026 and is listed in CISA KEV, so unpatched cPanel/WHM hosts are at immediate risk.

10.0 CVSS 4.0 Critical CISA KEV since 26 May 2026 EPSS 1.0% · top 38.3% CWE-266 · CWE-266
10.0CVSS 4.0 base score
1.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
4References
23 Jul 2026Last modified by NVD

Description

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score is 10.0, exploitation is confirmed in the wild, and CISA KEV lists it with a 2026-05-29 remediation due date.

What it is

The LiteSpeed User-End cPanel Plugin before 2.4.5 mishandles Redis enable/disable functionality, allowing privilege escalation that may reach root. It was exploited in the wild in May 2026 and is listed in CISA KEV, so unpatched cPanel/WHM hosts are at immediate risk.

Impact

An attacker can escalate privileges, potentially to root, gaining full control of the affected server and any hosted accounts.

Attack surface

Reachable over the network through the cPanel plugin interface with no authentication or user interaction required per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The flaw is triggered via the plugin's Redis enable/disable handling.

Exploitation

Active exploitation in the wild is confirmed by the description and CISA KEV addition on 2026-05-26; EPSS 30-day probability is 0.189 (97th percentile). No ransomware campaign use is documented.

What to do

  • Upgrade the LiteSpeed cPanel/WHM plugin to version 2.4.7 or later immediately.
  • If patching is not possible, disable or remove the LiteSpeed cPanel plugin until it can be updated.
  • Apply vendor mitigations from the LiteSpeed advisory and follow CISA BOD 22-01 guidance for cloud services.
  • Restrict network access to cPanel/WHM interfaces to trusted management networks.
  • Review cPanel and WHM accounts for unexpected privilege changes after patching.

Detection

  • Run grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null and investigate any matching entries.
  • Examine source IP addresses in matching log entries, block invalid or untrusted ones, and review system logs for activity from those IPs.
  • Monitor for unexpected Redis enable/disable actions and privilege changes in cPanel/WHM audit logs.
  • Alert on plugin version below 2.4.5 across managed servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-48172 to the Known Exploited Vulnerabilities catalog on 26 May 2026 as "LiteSpeed cPanel Plugin Privilege Escalation Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 29 May 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-48172 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-48172), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.