10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. LiteSpeed WHM Plugin (the parent plugin) is unaffected. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features.
AI Analysis
Privilege escalation vulnerability in LiteSpeed User-End cPanel Plugin before 2.4.5
Basic Information
ID
CVE-2026-48172
Source
mitre
Published
May 21, 2026 at 00:38
Affected Product
Vendor
LiteSpeed Technologies
Product
cPanel Plugin
Version
2.3
Affected Versions
LiteSpeed Technologies cPanel Plugin 2.3
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
LiteSpeed Technologies
Product
LiteSpeed User-End cPanel Plugin
Version
2.3