🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
LiteSpeed cPanel Plugin Privilege Escalation RCE Root (CVE-2026-48172) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateMay 23, 2026
CVECVE-2026-48172
CVSS Score9.8
Affectedlitespeed_cpanel_plugin, litespeed_whm_plugin
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin allows any cPanel user to execute arbitrary scripts with root privileges through incorrect privilege assignment. The vulnerability carries a maximum CVSS score of 10.0 and is being actively exploited in the wild. Any compromised cPanel account can escalate to full server control.
⚠️Why It Matters for MSSPs
Your clients running shared hosting environments with LiteSpeed and cPanel are exposed to complete server compromise through any low-privilege account breach. If you manage hosting infrastructure for clients or resell hosting services, one compromised website can lead to full server takeover affecting all hosted sites and potentially your management access.
✅Recommended Action
Identify all client environments running LiteSpeed cPanel Plugin and coordinate immediate patching or temporary plugin disabling within 24 hours.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.