Knox CVE Database
/
CVE-2026-48172
Critical
9.8

CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

Added to the CISA KEV catalog:
May 26, 2026

Overview

The LiteSpeed user-end cPanel plugin contains an incorrect privilege assignment flaw in its Redis enable/disable function. Any cPanel user account on an affected server can call this function to execute arbitrary scripts with root privileges, effectively taking full control of the host. Versions from 2.3 through 2.4.4 of the cPanel plugin are affected. Active exploitation was confirmed in May 2026, and the vulnerability is included in CISA's Known Exploited Vulnerabilities catalog.

Vulnerability details

Affected vendor
LiteSpeed
Affected product
cPanel Plugin
Weakness type (CWE)
CWE-266

The flaw is classified as CWE-266 (Incorrect Privilege Assignment). The plugin exposes the lsws.redisAble function through the cPanel JSON API, intended to let individual hosting users toggle Redis caching on or off for their accounts. Because the function executes with root privileges rather than the calling user's privileges, any cPanel account holder can invoke it to run arbitrary scripts as root. The trust boundary between unprivileged hosting users and the server's privileged runtime is not enforced at the API layer.


An attacker with any valid cPanel account on the target server sends a crafted API request specifying cpanel_jsonapi_func=redisAble to invoke the lsws.redisAble function. No elevated cPanel permissions are required beyond a basic hosting account, which can be legitimately purchased or obtained through a compromised credential. A successful call results in arbitrary script execution with root privileges, giving the attacker complete control over the server, including all hosted accounts, configuration files, and credentials stored on the system.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Search cPanel and LSWS log directories for exploitation attempts using the vendor-published command: grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/. Any output indicates a request was made to invoke the vulnerable function; a healthy server with no exploitation attempts produces no output.
  • For any log entries found by the above grep, extract the source IP addresses and cross-reference them against known hosting customers. IP addresses that do not correspond to legitimate account holders, or that appear in threat intelligence feeds, are strong indicators of active exploitation and warrant full system forensic review.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
May 29, 2026

Additional hardening

  • Upgrade the LiteSpeed cPanel plugin to version 2.4.7 (bundled with WHM plugin 5.3.1.0) or later. Both boundaries apply: cPanel plugin below 2.4.7 and WHM plugin below 5.3.1.0 are affected. See References for the vendor advisory.
  • If immediate upgrade is not possible, remove the user-end cPanel plugin entirely using the vendor-provided uninstall command (/usr/local/lsws/admin/misc/lscmctl cpanelplugin --uninstall) to eliminate the exposed API surface until patching is feasible.
  • Restrict cPanel API access at the network perimeter so that API calls can only originate from expected client IP ranges, reducing the pool of accounts that can reach the vulnerable function from arbitrary internet sources.
  • After patching, audit system logs for actions taken by any IP addresses identified in the cpanel_jsonapi_func=redisAble log search, and review for unauthorized files, cron jobs, or user accounts created with root privileges during the exposure window.

Key dates

Published (NVD)
May 20, 2026
Added to CISA KEV
May 26, 2026
Remediation deadline
May 29, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-48172 affect my FedRAMP authorization?

If LiteSpeed cPanel Plugin runs inside your authorization boundary, CVE-2026-48172 affects your FedRAMP authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of May 29, 2026 has already passed. An unpatched KEV in your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. At this point, you either remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-48172?

Knox does not patch LiteSpeed cPanel Plugin on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to own. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch stays with your team; managing your compliance posture while you do it does not have to be a solo effort.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-48172, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-48172's remediation deadline of May 29, 2026 has passed. What happens now?

An unremediated CVE-2026-48172 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and formally documenting the delay is what keeps your authorization intact and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.