CVE-2026-48172Active Exploitation(litespeedtech / litespeed_cpanel_plugin)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch litespeedtech litespeed_cpanel_plugin systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-29. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-266

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litespeed_cpanel_plugin
  • litespeed_whm_plugin

Threat summary

  • Active exploitation appears in 95 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 123 mentions across 26 observed days

What's happening

  • Active exploitation reported across 95 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 45 signals
  • Technical details provided in 88 signals
  • Disclosure: 12 classified signals
  • Peaked 23d ago at 22 mentions (2026-05-23); latest day: 1
  • 123 total mentions across 26 days

Affected systems

Products
litespeed_cpanel_pluginlitespeed_whm_plugin

Deep dive

Activity timeline123 mentions / 26d
06111722Mentions · 2026-05-21: 3Mentions · 2026-05-22: 8Mentions · 2026-05-23: 22Mentions · 2026-05-24: 8Mentions · 2026-05-25: 10Mentions · 2026-05-26: 12Mentions · 2026-05-27: 21Mentions · 2026-05-28: 7Mentions · 2026-05-29: 5Mentions · 2026-06-02: 1Mentions · 2026-06-03: 2Mentions · 2026-06-04: 1Mentions · 2026-06-05: 2Mentions · 2026-06-07: 4Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-10: 2Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-13: 2Mentions · 2026-06-16: 2Mentions · 2026-06-17: 2Mentions · 2026-07-19: 1Mentions · 2026-07-25: 2Mentions · 2026-07-31: 1Mentions · 2026-08-22: 1PoC Mentioned / Linked · 2026-05-22: 2PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-08-22: 1Exploit Tool / Code · 2026-05-27: 1Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-05-22: 7Active Exploitation · 2026-05-23: 20Active Exploitation · 2026-05-24: 5Active Exploitation · 2026-05-25: 8Active Exploitation · 2026-05-26: 9Active Exploitation · 2026-05-27: 15Active Exploitation · 2026-05-28: 5Active Exploitation · 2026-05-29: 2Active Exploitation · 2026-06-02: 1Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-07: 4Active Exploitation · 2026-06-10: 2Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-13: 2Active Exploitation · 2026-06-17: 2Active Exploitation · 2026-07-19: 1Active Exploitation · 2026-07-25: 2Active Exploitation · 2026-07-31: 1Active Exploitation · 2026-08-22: 1Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-23: 8Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-25: 5Patch / Workaround · 2026-05-26: 5Patch / Workaround · 2026-05-27: 10Patch / Workaround · 2026-05-28: 6Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-13: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-07-19: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 4Technical Details · 2026-05-23: 16Technical Details · 2026-05-24: 8Technical Details · 2026-05-25: 9Technical Details · 2026-05-26: 10Technical Details · 2026-05-27: 14Technical Details · 2026-05-28: 3Technical Details · 2026-05-29: 3Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 2Technical Details · 2026-06-05: 1Technical Details · 2026-06-07: 2Technical Details · 2026-06-09: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-13: 2Technical Details · 2026-06-16: 2Technical Details · 2026-06-17: 2Technical Details · 2026-07-19: 1Technical Details · 2026-07-25: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-22: 105-2105-2305-2505-2705-2906-0306-0506-0806-1006-1206-1607-1907-3108-22
Signal classification6 categories
Active Exploitation
8972.4%
Patch
1613.0%
Disclosure
129.8%
General
32.4%
Exploit
21.6%
False Positive
10.8%
Referenced assets89 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-213
Active Exploitation3
2026-05-228
Active Exploitation7Disclosure1
2026-05-2322
Active Exploitation20False Positive1Patch1
2026-05-248
Active Exploitation5Disclosure2Patch1
2026-05-2510
Active Exploitation7Patch3
2026-05-2612
Active Exploitation9Disclosure2Patch1
2026-05-2721
Active Exploitation14Disclosure2Exploit1General1Patch3
2026-05-287
Active Exploitation4Patch3
2026-05-295
Active Exploitation2Disclosure2Patch1
2026-06-021
Active Exploitation1
2026-06-032
Active Exploitation2
2026-06-041
Active Exploitation1
2026-06-052
Disclosure2
2026-06-074
Active Exploitation4
2026-06-081
General1
2026-06-091
General1
2026-06-102
Active Exploitation2
2026-06-111
Active Exploitation1
2026-06-121
Active Exploitation1
2026-06-132
Active Exploitation1Patch1
2026-06-162
Disclosure1Patch1
2026-06-172
Active Exploitation2
2026-07-191
Patch1
2026-07-252
Active Exploitation2
2026-07-311
Active Exploitation1
2026-08-221
Exploit1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Active exploit: LiteSpeed cPanel root flaw. https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html CVE-2026-48172 is a CVSS 10.0 vulnerability in LiteSpeed User-End cPanel Plugin that lets any cPanel user run arbitrary scripts as root. 🔸 Affected: v2.3–2.4.4 🔸 Not affected: WHM plugin 🔸 Fix: upgrade to WHM Plugin 5.3.1.0 with cPanel plugin v2.4.7+ 🔸 IOC: cpanel_jsonapi_func=redisAble

    Post summary

    The post announces that LiteSpeed cPanel’s CVE‑2026‑48172 is being actively exploited, provides technical details, and gives a patch recommendation.

    1272821516.3K
    1.9M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added LiteSpeed cPanel Plugin privilege escalation vulnerability CVE-2026-48172 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/ESxbREvODw

    Post summary

    The tweet indicates CVE-2026-48172 is recognized as a known exploited vulnerability for LiteSpeed cPanel Plugin, with no further details or mitigation information provided.

    41323218.7K
    300.1K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Explotan vulnerabilidad CVE-2026-48172 en plugin de LiteSpeed para cPanel para ejecutar scripts como root https://blog.elhacker.net/2026/05/explotan-vulnerabilidad-cve-2026-48172.html

    Post summary

    The post reports that CVE‑2026‑48172 in LiteSpeed’s cPanel plugin is actively exploited to execute root‑privilege scripts, with no mention of patches or proof‑of‑concept details.

    07022102.4K
    141.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    CVE-2026-48172: Critical LiteSpeed cPanel Plugin Flaw Exploited for Privilege Escalation https://darkwebinformer.com/cve-2026-48172-critical-litespeed-cpanel-plugin-flaw-exploited-for-privilege-escalation/

    Post summary

    CVE-2026-48172, a critical flaw in the LiteSpeed cPanel plugin, has reportedly been leveraged for privilege escalation attacks, indicating active exploitation in the wild. No patch or mitigation details are provided.

    1402085.1K
    223.7K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html

    Post summary

    The article indicates that CVE‑2026‑48172 in the LiteSpeed cPanel plugin is actively exploited, enabling attackers to execute scripts with root privileges.

    0101542.3K
    158.6K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Urgent: Active attacks target the LiteSpeed User-End cPanel Plugin (CVE-2026-48172). Learn how to detect the exploit and secure your server root today. #LiteSpeed #cPanel #VulnerabilityAlert #CVE202648172 #WebHosting #RootAccess #CyberSecurity #InfoSec https://securityonline.info/litespeed-cpanel-plugin-privilege-escalation-cve-2026-48172/ https://t.co/W1GTAqrrFb

    Post summary

    The tweet announces that CVE-2026-48172 is currently being actively exploited against the LiteSpeed User-End cPanel Plugin and urges administrators to detect and mitigate the threat.

    02062741
    12.5K followersView on X
  • Florian Hansemann@CyberWarship
    Active Exploitation

    ''LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root'' #infosec #pentest #redteam #blueteam https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html

    Post summary

    The tweet references a headline asserting that CVE-2026-48172 is being actively exploited to run scripts as root on LiteSpeed cPanel, though no further details are provided.

    020521.5K
    88.5K followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Active Exploitation

    おはモー🐮 【WP×サーバー警鐘】CISA KEVにも追加されたLiteSpeed cPanel権限昇格(CVE-2026-48172)、対処期限が5/29モー🐮 国内WPには毎日数千件の攻撃検知、断捨離+監視の二段構えが現実解だモー🐮 今日のチェック2点だモー: ✅ サーバーの cPanel/LiteSpeed バージョン確認 ✅ 「PHP 5.x or WP 4.x で動いてる古いサイト」棚卸し #おは戦80527ms🌊 #WordPressセキュリティ

    Post summary

    CVE‑2026‑48172, a privilege‑escalation flaw in LiteSpeed cPanel, has been added to CISA KEV and is actively exploited; administrators are urged to update to a patched version before the 5/29 deadline.

    20070167
    870 followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    LiteSpeed cPanelプラグインの重大脆弱性が実際に悪用されていることが判明した。リモート攻撃者は権限昇格を実行し、対象サーバーを完全制御できる可能性がある。 問題はLiteSpeed User-End cPanel Pluginに存在するCVE-2026-48172で、Redis有効化・無効化機能「redisAble」の処理不備に起因する。 既に2026年5月時点で実際の悪用が確認されており、cPanel環境の緊急点検が推奨されている。 LiteSpeedは侵害確認用として、「cpanel_jsonapi_func=redisAble」を含むログ検索コマンドを公開した。該当ログが存在する場合、攻撃試行を受けた可能性が高く、対象IPアドレスの調査と遮断、追加ログ確認が必要になる。 修正版は2026年5月21日に公開され、cPanel Plugin 2.4.7以上(WHM Plugin v5.3.1.0同梱)への更新が必要となる。最新版ではRedis脆弱性修正に加え、入力検証強化、コマンドインジェクション対策、adminbin認証強化、QuicCloud IP検証改善など複数のハードニングも導入された。 さらに新規インストール時にはcPanelプラグイン自動導入がデフォルト無効化となり、攻撃対象領域を縮小している。ホスティング事業者や管理者には即時パッチ適用が強く求められている。 https://securityonline.info/litespeed-cpanel-plugin-privilege-escalation-cve-2026-48172/

    Post summary

    CVE‑2026‑48172 in the LiteSpeed cPanel Plugin is actively exploited, enabling remote attackers to elevate privileges and potentially seize full control of the server. A patch is available and an urgent update is recommended.

    010801.5K
    14.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/26追加) 🛡️No.1604 CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:不適切な権限設定 (CWE-266) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H LiteSpeed User-End cPanel Plugin 2.4.5未満には、権限昇格の脆弱性が存在します。Redisの有効化・無効化機能の不適切な処理に関連しているものです。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・LiteSpeed User-End cPanel Plugin の影響バージョンが稼働していること。ベンダーは v2.3 から v2.4.4 までが影響すると案内。 ・攻撃者がcPanelユーザーとしてログイン可能であること。 ・認証済みのcPanelユーザーから lsws.redisAble 機能を呼び出せること。 ✅悪用時影響 ・特権昇格をされる ・任意のスクリプトを特権で実行される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。LiteSpeedはこの脆弱性がアクティブに悪用されていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-48172 https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ https://www.cisa.gov/news-events/alerts/2026/05/26/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA has added CVE-2026-48172 to its Known Exploited Vulnerabilities catalog, confirming that the LiteSpeed cPanel Plugin vulnerability is actively exploited; vendor has issued a security update.

    000624.9K
    43.9K followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Patch

    おはモー🐮 【明日が期限】LiteSpeed cPanel CVE-2026-48172、CISA KEV対処期限が明日5/29モー🐮 未対応のままで週末突入は最悪のパターン、共用サーバー組は今日中にホスティング業者に: ✅ パッチ適用済みか確認 ✅ 未対応なら明日中の対応スケジュール 木曜の朝5分で、週末の事故ゼロを買うモー🐮 #おは戦80528mm🌴 #WordPressセキュリティ

    Post summary

    The tweet alerts operators to the imminent CISA KEV deadline for CVE‑2026‑48172 and urges them to verify and apply the patch or schedule remediation promptly.

    10040154
    870 followersView on X
  • Gray Hats@the_yellow_fall
    Exploit

    The LiteSpeed cPanel plugin exploit (CVE-2026-48172) allows attackers to escape shared hosting sandboxes and gain root access. Learn how to patch it now. #LiteSpeed #cPanel #WebHosting #CVE202648172 #RootAccess #PrivilegeEscalation #SysAdmin https://meterpreter.org/litespeed-cpanel-plugin-exploit-root-privilege-escalation/ https://t.co/F2XA5lJuBS

    Post summary

    The post advertises a functional exploit for CVE‑2026‑48172 that enables sandbox escape and root privilege escalation on LiteSpeed cPanel, while urging administrators to apply a patch.

    00040478
    12.5K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    1/2 LiteSpeed User-End cPanel Plugin has a maximum-severity privilege escalation flaw under active exploitation. CVE-2026-48172, CVSS 10.0. Any cPanel user can run arbitrary scripts as root via the lsws.redisAble function.

    Post summary

    The post reports that CVE‑2026‑48172, a privilege‑escalation flaw in LiteSpeed’s cPanel Plugin, is actively exploited, letting users run arbitrary scripts as root via the lsws.redisAble function.

    1102094
    181 followersView on X
  • Blue Team News@blueteamsec1
    Exploit

    LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root http://dlvr.it/TV7Vhz #LiteSpeed #CVE202648172 #cPanel #CyberSecurity #Vulnerability https://t.co/6R3xGzykU3

    Post summary

    The tweet announces that CVE‑2026‑48172 was exploited to run scripts as root and links to likely PoC or exploit details, indicating both the existence of a PoC and active exploitation, but without vendor mitigation information.

    010012.0K
    57.0K followersView on X
  • BnSnK@BunSnack
    Disclosure

    CVE-2026-48172 (CVSS 10.0): LiteSpeed User-End cPanel Plugin. Any attacker with a foothold executes scripts as root. 740,000+ verified installations. Same ecosystem as the 40k-server cPanel breach. https://nvd.nist.gov/vuln/detail/CVE-2026-48172

    Post summary

    A high‑severity CVE (CVE‑2026‑48172) affecting the LiteSpeed User‑End cPanel Plugin is disclosed, noting that attackers with a foothold can execute scripts as root. No patch or exploitation evidence is provided.

    000205
    6 followersView on X
  • Decryption Digest ®@DecryptionDigst
    Patch

    CVSS 10.0: any cPanel tenant becomes root via CVE-2026-48172. CISA deadline is today. LiteSpeed WHM Plugin v5.3.1.0 closes the gap. Scan logs for cpanel_jsonapi_func=redisAble now. Full IOCs at http://decryptiondigest.com #CVE202648172 #cPanel #LiteSpeed #CISA #PatchNow #WebSecurity https://t.co/jqTtRugO76

    Post summary

    A CVSS 10.0 critical vulnerability (CVE‑2026‑48172) allows cPanel tenants to become root; LiteSpeed WHM Plugin v5.3.1.0 is the available patch and must be applied to close the exploit window.

    10010160
    16 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    LiteSpeed cPanel プラグインのゼロデイ CVE-2026-48172 が FIX:サーバ root 権限奪取の恐れ https://iototsecnews.jp/2026/05/23/litespeed-cpanel-plugin-0-day-exploited-for-server-root-access/ 今回の脆弱性 CVE-2026-48172 の原因は、プラグインのエンドポイントに存在する、プログラムのロジックの欠陥に起因します。本来であれば、厳しく制限されるべき API が、ログインしているユーザー全員にデフォルトで公開されたことで、単一の不正なリクエストだけで root 権限を奪われる仕組みになっていました。さらに、この環境では、同じ時期に CVE-2026-41940 という別の認証バイパスの脆弱性も確認されています。ご利用のチームは、ご注意ください。 #cPanel #CVE202648172 #Litespeed #Vulnerability

    Post summary

    The article announces a zero‑day vulnerability (CVE‑2026‑48172) in the LiteSpeed cPanel plugin, detailing how a logic flaw allows root privilege escalation but does not provide PoC, exploit code, or evidence of active exploitation.

    10010111
    491 followersView on X
  • Tobibur Rahman@tobi8ur
    Patch

    CISA ordered agencies to patch or remove the LiteSpeed cPanel user-end plugin after zero-day attacks on CVE-2026-48172 enabled root-level script execution. If your hosting plugin needs a KEV deadline, it was never just a plugin. #AppSec #Cybersecurity

    Post summary

    CISA has mandated agencies to patch or remove the LiteSpeed cPanel user‑end plugin due to zero‑day attacks on CVE‑2026‑48172 that allow root‑level script execution.

    1001095
    75 followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Patch

    おはモー🐮 【期限当日】LiteSpeed cPanel CVE-2026-48172、CISA KEV対処期限が今日5/29モー🐮 しかも StarletteのBadHost(CVE-2026-48710)も新たに来たモー… 今日の朝5分で: ✅ cPanelパッチ適用状況の最終確認 ✅ FastAPI/vLLM系AIサーバー使ってるなら Starlette 1.0.1+ 確認 金曜の朝に締めて、週末を安心して迎えるモー🐮 #おは戦80529mk🍺 #WordPressセキュリティ

    Post summary

    The post serves as a reminder to verify patch application for LiteSpeed cPanel (CVE-2026-48172) and to upgrade Starlette to mitigate CVE-2026-48710, without any evidence of exploits or PoC.

    1001089
    758 followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA adds CVE-2026-48172 to Known Exploited Vulnerabilities catalog. LiteSpeed cPanel plugin flaw (CVSS 10.0) allows attackers to run arbitrary scripts as root via incorrect privilege assignment. Actively exploited in the wild. FCEB agencies must patch by June 16. Source: CISA / The Hacker News Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    CISA has highlighted CVE-2026-48172 as actively exploited in the wild, urging agencies to apply patches by June 16.

    01010134
    182 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Applitespeedtechlitespeed_cpanel_plugin---
Applitespeedtechlitespeed_whm_plugin---

Explore more