Critical LiteSpeed Flaw Could Let One Website Take Over a Shared Server
cPanel has warned of a critical vulnerability in LiteSpeed Web Server Enterprise that could allow a low-privilege website user on a shared hosting server to gain root access. On shared servers, many customers' websites run on the same machine, so an attacker exploiting this flaw could potentially access or modify other customers' sites and the underlying server itself.
The flaw affects LiteSpeed versions before 6.3.7 and can bypass isolation tools such as CageFS, which normally restrict what each hosting account can see on the file system. Neither cPanel nor LiteSpeed has published technical details on how the flaw works, and no CVE identifier or severity score has been assigned as of the time of the advisory. It is also unclear whether the flaw has been exploited in the wild.
LiteSpeed released version 6.3.7 on September 11 to address the issue, but the fix may take time to reach servers through auto-update. Both companies recommend administrators manually force the update using a provided command, and note that this temporarily takes the server off its stable update tier until manually reset. The current stable download listed as of September 15 was still the older, vulnerable 6.3.6 version.