Vulnerability Management

Critical LiteSpeed Enterprise flaw allows shared hosting account to gain root access

Magnifying glass red bug bounty, green binary code, identify and submit vulnerability reports

A critical vulnerability has been identified in LiteSpeed Enterprise that could allow a low-privilege website user to gain root access to the entire server, bypassing security measures like CageFS, cPanel warns. This could lead to a complete compromise of shared hosting environments, enabling attackers to access or modify other hosted websites and the server itself, Security Affairs reports.

The privilege-escalation flaw affects LiteSpeed Web Server Enterprise versions prior to 6.3.7. It specifically bypasses account isolation controls, including CageFS, which is designed to restrict each hosting account's view of the filesystem. This means a single compromised account could potentially read or alter other websites on the same server and gain full control of the machine. Neither cPanel nor LiteSpeed has disclosed technical details of the vulnerability, and it is unclear if it is being actively exploited.

LiteSpeed has released version 6.3.7 to address the issue, urging administrators to update their installations using a specific command. For systems that cannot be patched immediately, there is no known workaround. This advisory applies only to the Enterprise edition; the open-source OpenLiteSpeed variant is not affected. This marks the third root-level escape vulnerability linked to LiteSpeed on cPanel shared-hosting servers since May.

Source: Security Affairs

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds