Back to Labs
Security Advisory

CVE-2026-48172

About

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

Weakness (CWE):CWE-266

Rainforest analyst review

The LiteSpeed cPanel/WHM plugin mishandles its Redis enable/disable functionality in a way that allows privilege escalation, potentially to root, on the hosting server. The weakness is reached through the cPanel JSON API `redisAble` function, and the vendor's own detection guidance — grepping cPanel logs for `cpanel_jsonapi_func=redisAble` — points at that call being the exploitation vector, so an attacker abusing the Redis feature elevates from limited access to control of the system.

On a shared-hosting server, a privilege escalation to root is a breach of the whole tenancy: cPanel boxes host many customers' sites and data side by side, so root turns a single foothold into compromise of every account on the machine. The flaw was exploited in the wild in May 2026, so exposed servers should be treated as targets rather than hypothetical risk. Update to at least version 2.4.7 as the vendor recommends, and run the provided log grep on affected systems; if it returns hits, investigate the source IP addresses, block those that are illegitimate, and work through system logs to scope any damage before assuming the update alone closed the incident.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2026-48172?

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability.

How severe is CVE-2026-48172?

CVE-2026-48172 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2026-48172 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2026-48172?

Public advisories list the following as affected: litespeed cpanel plugin, litespeed whm plugin. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2026-48172?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email