Threat Intelligence

Critical LiteSpeed Flaw Could Let One Website Take Over a Shared Server

The Hacker News · 15 Sept 2026
Key Takeaway If your business uses shared hosting with LiteSpeed Enterprise, ask your hosting provider to confirm they have manually updated to version 6.3.7 or later rather than assuming auto-update has applied the fix.

cPanel has warned of a critical vulnerability in LiteSpeed Web Server Enterprise that could allow a low-privilege website user on a shared hosting server to gain root access. On shared servers, many customers' websites run on the same machine, so an attacker exploiting this flaw could potentially access or modify other customers' sites and the underlying server itself.

The flaw affects LiteSpeed versions before 6.3.7 and can bypass isolation tools such as CageFS, which normally restrict what each hosting account can see on the file system. Neither cPanel nor LiteSpeed has published technical details on how the flaw works, and no CVE identifier or severity score has been assigned as of the time of the advisory. It is also unclear whether the flaw has been exploited in the wild.

LiteSpeed released version 6.3.7 on September 11 to address the issue, but the fix may take time to reach servers through auto-update. Both companies recommend administrators manually force the update using a provided command, and note that this temporarily takes the server off its stable update tier until manually reset. The current stable download listed as of September 15 was still the older, vulnerable 6.3.6 version.

LiteSpeed shared hosting privilege escalation cPanel server security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.