LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
- ID
- 24578
- Status
- summarized
- Published
- 15 Sep 2026, 2:52 PM
- Fetched
- 15 Sep 2026, 5:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 15 Sep 2026, 5:17 PM
- Tags
- Audience
- developerssaas_founders
What happened
A critical privilege-escalation flaw in LiteSpeed Web Server Enterprise (versions before 6.3.7) could let any low-privilege hosting account gain root on a shared server, bypassing CageFS isolation. cPanel issued an advisory on September 14 urging manual updates to 6.3.7 (released September 11), since auto-update may be delayed and 6.3.6 is still listed as stable on LiteSpeed's download page. No CVE, no severity score, and no public detail on which changelog entry fixes it.
Why it matters
If you run or rent on a shared cPanel/LiteSpeed server — common among Malaysian small businesses and budget hosting — your site's isolation from neighbors is broken until the admin runs the manual update command. Ask your hosting provider whether they've applied 6.3.7; if you administer the box yourself, run the forced update now and resume stable-tier tracking afterward.
Discussion angle
How many Malaysian startups and SMEs are silently exposed because their shared hosting provider hasn't manually bumped LiteSpeed past 6.3.6 — and whether you should audit your own hosting stack or move off shared hosting entirely.