---
id: CVE-2026-48172
title: >-
  LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation
  (possibly to root), as exploited in the wild in May 2026
summary: >-
  LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation
  (possibly to root), as exploited in the wild in May 2026. Detection is best
  done via a command line of grep -rE "cpanel_jsonapi_func=redisAble"
  /var/cpanel/logs /u…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-266
vendor: litespeedtech
product: litespeed_cpanel_plugin
affected:
  - litespeed_cpanel_plugin < 2.4.7
  - litespeed_whm_plugin < 5.3.1.0
patched:
  - litespeed_cpanel_plugin 2.4.7
  - litespeed_whm_plugin 5.3.1.0
published: '2026-05-21'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:37.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48172'
references:
  - url: >-
      https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/
    label: cve@mitre.org
  - url: >-
      https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel
    label: cve@mitre.org
  - url: >-
      https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log
    label: cve@mitre.org
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48172
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.01011
epssPercentile: 0.61967
kev: true
kevDateAdded: '2026-05-26'
kevDueDate: '2026-05-29'
kevRansomware: false
exploited: true
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-48172'
    - 'https://github.com/retmakarunia/CVE-2026-48172'
    - >-
      https://github.com/fevar54/CVE-2026-48172---LiteSpeed-cPanel-Plugin-Version-Auditor
  checkedAt: '2026-10-07T20:47:22.833Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-05-27T03:55:25.936300Z'
scores:
  nvd: 9.8
  cna: 10
ingestedAt: '2026-10-07T18:42:20.902Z'
---

## Overview

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

## Affected

- `litespeed_cpanel_plugin < 2.4.7`
- `litespeed_whm_plugin < 5.3.1.0`

## Remediation

Upgrade past the affected range:

- `litespeed_cpanel_plugin 2.4.7`
- `litespeed_whm_plugin 5.3.1.0`
