Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-48172

Published 2026-05-21
Updated 2 months ago
Vendor/s
LiteSpeed
Product/s
cPanel Plugin
Version/s
* > 2.4.7
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-48172 is a critical (CVSS 9.8) privilege escalation vulnerability in LiteSpeed cPanel plugins actively exploited in the wild.

CPE

LiteSpeed logo
LiteSpeed
Product Version Start Version End (excl.) Status
litespeed_cpanel_plugin * 2.4.7 vulnerable
litespeed_whm_plugin * 5.3.1.0 vulnerable

Related weakness (CWE)

CWE-266

Remediation plan

1

Apply official patches

Immediately install the security updates provided by LiteSpeed Technologies. The vendor has released patches to address the logic flaw in the Redis management component; upgrading to version 2.4.7 or higher is required to mitigate the risk.

2

Update affected systems

Verify that the LiteSpeed cPanel Plugin is running version 2.4.7 or later. Additionally, ensure the LiteSpeed WHM Plugin is updated to version 5.3.1.0 or higher, as these versions contain the necessary fixes to prevent privilege escalation.

3

Restrict access

Implement strict IP whitelisting for access to cPanel and WHM management ports. If the Redis management feature is not essential for your operations, consider disabling the plugin functionality or blocking external access to the cPanel API until the environment is fully secured.

4

Monitor for exploitation

Audit system logs for unauthorized privilege escalations or suspicious administrative activity. Focus on identifying unknown IP addresses interacting with the cPanel API, particularly those attempting to modify Redis configurations or executing commands with elevated permissions.

Detection Guidance

"Administrators can detect exploitation attempts by searching cPanel logs for the 'redisAble' function. Execute the command: grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/. If results are returned, investigate the associated IP addresses for malicious activity. Presence of this string in logs, combined with unfamiliar IPs or unexpected root-level processes, is a strong indicator of an attempted or successful compromise via this vulnerability."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management