The broken assumption is that a cPanel user’s permissions contain the damage. In LiteSpeed’s user-end cPanel plugin, any tenant account can abuse lsws.redisAble to run scripts as root, so one compromised hosting account can turn into full server compromise.
LiteSpeed says CVE-2026-48172 is being actively exploited and fixed it in plugin 2.4.5. The affected range is 2.3 through 2.4.4, and LiteSpeed published a log grep indicator, cpanel_jsonapi_func=redisAble, to help operators find exposed hosts.
For shared hosting providers, account-level containment is the wrong model if this marker appears. The question shifts from one bad cPanel user to whether the host itself is already trusted compromised.