LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
What happened
cPanel issued an advisory on September 14 warning that a vulnerability in LiteSpeed Web Server Enterprise allows a low-privilege hosting account to bypass isolation controls like CageFS and gain root access on shared servers. The flaw affects versions prior to 6.3.7, which LiteSpeed released on September 11, and requires manual installation via the `lsup.sh` script because automatic updates may be delayed.
Why it ranks #1
cPanel issued an advisory on September 14 warning that a vulnerability in LiteSpeed Web Server Enterprise allows a low-privilege hosting account to bypass isolation controls like CageFS and gain root access on shared servers.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
Update cPanel to version 6.3.7, released September 11, to address the flaw affecting earlier versions.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- product
- Status
- actively exploited