SB2026052520 - Privilege escalation in LiteSpeed User-End cPanel Plugin
Published: May 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect Privilege Assignment (CVE-ID: CVE-2026-48172)
CWE-ID: CWE-266 - Incorrect Privilege Assignment
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/U:Red
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to incorrect privilege assignment. A remote authenticated cPanel user can abuse the lsws.redisAble function to execute arbitrary scripts as root.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.