Executive brief
A vulnerability in the LiteSpeed plugin for cPanel allows standard users to gain full administrative control over the web hosting server. This plugin is used by hosting providers to manage web server performance and features for their customers. An attacker can exploit this flaw to execute commands with root privileges, potentially leading to total system takeover, data theft, and service disruption.
Technical details
The LiteSpeed User-End cPanel Plugin before version 2.4.5 is vulnerable to an incorrect privilege assignment (CWE-266) related to the mishandling of Redis enable/disable features. Specifically, the vulnerability is exposed via the 'redisAble' function in the user-end plugin's JSON API. A remote attacker with access to a standard cPanel user account can exploit this flaw to escalate privileges to root. This vulnerability has been observed being exploited in the wild as of May 2026. Administrators can check for exploitation by searching cPanel logs for the 'cpanel_jsonapi_func=redisAble' string. The LiteSpeed WHM (parent) plugin is reportedly unaffected.
Affected products
- LiteSpeed User-End cPanel Plugin before 2.4.5
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
- 2026-05-26: other: NVD Publication Date
- 2026-05-01: exploited: Exploitation reported in the wild in May 2026