A critical vulnerability has been identified in LiteSpeed Enterprise that could allow a low-privilege website user to gain root access to the entire server, bypassing security measures like CageFS, cPanel warns. This could lead to a complete compromise of shared hosting environments, enabling attackers to access or modify other hosted websites and the server itself, Security Affairs reports.The privilege-escalation flaw affects LiteSpeed Web Server Enterprise versions prior to 6.3.7. It specifically bypasses account isolation controls, including CageFS, which is designed to restrict each hosting account's view of the filesystem. This means a single compromised account could potentially read or alter other websites on the same server and gain full control of the machine. Neither cPanel nor LiteSpeed has disclosed technical details of the vulnerability, and it is unclear if it is being actively exploited.LiteSpeed has released version 6.3.7 to address the issue, urging administrators to update their installations using a specific command. For systems that cannot be patched immediately, there is no known workaround. This advisory applies only to the Enterprise edition; the open-source OpenLiteSpeed variant is not affected. This marks the third root-level escape vulnerability linked to LiteSpeed on cPanel shared-hosting servers since May.Source: Security Affairs
Vulnerability Management
Critical LiteSpeed Enterprise flaw allows shared hosting account to gain root access
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
