← Back to Vulnerability Reports CVE Intelligence

CVE-2026-48172

LiteSpeed CPanel PluginCRITICAL · CVSS 9.8 In the wild In CISA KEV

What is CVE-2026-48172?

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

CVSS9.8 NVD 3.1
SeverityCRITICAL
Exploitation In the wild In CISA KEV
EPSS8% · P92
Triage statusActive Exploit
ActionPatch immediately
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD published2026-05-21
NVD last modified2026-05-26

CISA Known Exploited Vulnerability

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

Added to KEV2026-05-26
Federal patch deadline2026-05-29
Known ransomware useUnknown

Affected product

LiteSpeed CPanel Plugin

NVD also lists CPE entries for: Litespeedtech Litespeed Cpanel Plugin, Litespeedtech Litespeed Whm Plugin

Remediation Steps

  1. Apply the latest security patch from LiteSpeed for the cPanel Plugin immediately
  2. Verify that only authorized cPanel users have access to affected systems
  3. Review system logs for evidence of exploitation or unauthorized script execution
  4. Restrict cPanel administrative access to trusted networks where feasible
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.