SB2026052520 - Privilege escalation in LiteSpeed User-End cPanel Plugin



SB2026052520 - Privilege escalation in LiteSpeed User-End cPanel Plugin

Published: May 25, 2026

Security Bulletin ID SB2026052520
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect Privilege Assignment (CVE-ID: CVE-2026-48172)

CWE-ID: CWE-266 - Incorrect Privilege Assignment

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/U:Red


The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to incorrect privilege assignment. A remote authenticated cPanel user can abuse the lsws.redisAble function to execute arbitrary scripts as root.

Note, the vulnerability is being actively exploited in the wild. 


Remediation

Install update from vendor's website.