Vulnerabilities
LiteSpeed cPanel Plugin Flaw CVE-2026-48172 Lets Any Account Run Code as Root, Exploited Now
CVE-2026-48172, a CVSS 10.0 flaw in the LiteSpeed User-End cPanel plugin, lets anyone with a valid cPanel account run code as root. LiteSpeed confirms it is being actively exploited. On shared hosting, one cheap account is now a path to every account on the server.