A critical security vulnerability affecting LiteSpeed Web Server Enterprise could allow a low-privilege website user to gain root-level access to a server, according to a security advisory published by cPanel.
The issue is particularly important for shared-hosting environments, where multiple websites and customer accounts may operate on the same server.
According to cPanel’s security advisory, an attacker with access to a low-privilege website account could potentially use the vulnerability to escape normal account restrictions and gain elevated access to the underlying server.
Root access is the highest level of administrative access on a Linux server. If successfully exploited, the vulnerability could allow an attacker to access or modify other websites hosted on the same system, as well as make changes to the server itself.
The vulnerability can also bypass expected account-isolation protections, including CageFS. CageFS is commonly used on shared-hosting servers to keep individual hosting accounts separated from one another. Each user is placed inside a restricted environment intended to prevent access to other customers’ files and sensitive parts of the server.
cPanel lists LiteSpeed Web Server Enterprise versions prior to 6.3.7 as affected by the vulnerability. Administrators are being advised to upgrade affected installations to LiteSpeed Web Server Enterprise v6.3.7 Build 2 or later. Those who previously upgraded to version 6.3.7 should update again to ensure they have Build 2 or a newer release.
LiteSpeed’s release history shows additional security changes in version 6.3.7, including stronger lscgid request authentication and validation, additional internal redirect validation and further hardening of the lscgid component.
Website owners on managed or shared hosting may not have direct access to update LiteSpeed and should check with their hosting provider if they are unsure whether the server has been patched. Administrators managing LiteSpeed Enterprise directly should verify that they are running version 6.3.7 Build 2 or later, including systems that were previously updated to an earlier 6.3.7 build. cPanel’s advisory provides additional guidance for updating affected installations and verifying the installed release.

Leave a Reply