A significant security flaw has been identified in LiteSpeed Web Server Enterprise, potentially allowing low-privileged users to gain root access on shared hosting servers. cPanel disclosed this vulnerability in an advisory issued on September 14, 2026, urging administrators to upgrade to the latest software version.
Vulnerability Details and Risks
The vulnerability, affecting versions earlier than 6.3.7, poses a threat to shared servers hosting multiple websites on a single machine. An attacker could exploit this flaw to access and modify other sites or the server itself, as highlighted in cPanel’s advisory.
cPanel emphasized the necessity of updating to version 6.3.7, which LiteSpeed released on September 11. This update aims to address the flaw, which could bypass isolation mechanisms like CageFS, a CloudLinux tool designed to restrict each account’s view of the file system.
Update Instructions and Challenges
Administrators are advised to manually update to LiteSpeed version 6.3.7 using the command: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. This step is crucial since the update may not automatically deploy, as LiteSpeed noted potential delays in the automatic update process.
As of September 15, the LiteSpeed download page still listed version 6.3.6 as the stable release, with no mention of the recent security enhancements in the pre-release 6.4.0 (RC1). It’s important for server administrators to ensure their systems are updated to mitigate potential risks.
Previous Vulnerabilities and Current Concerns
This incident marks the third reported LiteSpeed software vulnerability since May that could allow root access on cPanel servers. Earlier, in May and June, two different vulnerabilities were identified and fixed in the LiteSpeed cPanel plugin, which were actively exploited, according to CVE reports.
Despite the release of version 6.3.7, neither cPanel nor LiteSpeed has provided a workaround for servers unable to update immediately or indicators to check if a server has been compromised. The current advisory also does not mention OpenLiteSpeed, the open-source counterpart, which remains without a corresponding update.
For the security of their web environments, administrators should prioritize these updates and stay informed about potential vulnerabilities, ensuring their systems are safeguarded against unauthorized access.
