LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
The LiteSpeed user-end cPanel plugin contains an incorrect privilege assignment flaw in its Redis enable/disable function. Any cPanel user account on an affected server can call this function to execute arbitrary scripts with root privileges, effectively taking full control of the host. Versions from 2.3 through 2.4.4 of the cPanel plugin are affected. Active exploitation was confirmed in May 2026, and the vulnerability is included in CISA's Known Exploited Vulnerabilities catalog.
The flaw is classified as CWE-266 (Incorrect Privilege Assignment). The plugin exposes the lsws.redisAble function through the cPanel JSON API, intended to let individual hosting users toggle Redis caching on or off for their accounts. Because the function executes with root privileges rather than the calling user's privileges, any cPanel account holder can invoke it to run arbitrary scripts as root. The trust boundary between unprivileged hosting users and the server's privileged runtime is not enforced at the API layer.
An attacker with any valid cPanel account on the target server sends a crafted API request specifying cpanel_jsonapi_func=redisAble to invoke the lsws.redisAble function. No elevated cPanel permissions are required beyond a basic hosting account, which can be legitimately purchased or obtained through a compromised credential. A successful call results in arbitrary script execution with root privileges, giving the attacker complete control over the server, including all hosted accounts, configuration files, and credentials stored on the system.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/. Any output indicates a request was made to invoke the vulnerable function; a healthy server with no exploitation attempts produces no output./usr/local/lsws/admin/misc/lscmctl cpanelplugin --uninstall) to eliminate the exposed API surface until patching is feasible.cpanel_jsonapi_func=redisAble log search, and review for unauthorized files, cron jobs, or user accounts created with root privileges during the exposure window.If LiteSpeed cPanel Plugin runs inside your authorization boundary, CVE-2026-48172 affects your FedRAMP authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of May 29, 2026 has already passed. An unpatched KEV in your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. At this point, you either remediate it or formally document the mitigation and the delay.
Knox does not patch LiteSpeed cPanel Plugin on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to own. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch stays with your team; managing your compliance posture while you do it does not have to be a solo effort.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-48172, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-48172 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and formally documenting the delay is what keeps your authorization intact and the agency relationship on solid footing.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








