Shared cPanel Hosts Face Root Compromise Risk

The broken assumption is that a cPanel user’s permissions contain the damage. In LiteSpeed’s user-end cPanel plugin, any tenant account can abuse lsws.redisAble to run scripts as root, so one compromised hosting account can turn into full server compromise. LiteSpeed says CVE-2026-48172 is being actively exploited and fixed it in plugin 2.4.5. The affected range is 2.3 through 2.4.4, and LiteSpeed published a log grep indicator, cpanel_jsonapi_func=redisAble, to help operators find exposed hosts. For shared hosting providers, account-level containment is the wrong model if this marker appears. The question shifts from one bad cPanel user to whether the host itself is already trusted compromised.

Part of the PlainSec briefing for 2026-05-24

Sources