Zurück zu den Sicherheitshinweisen

Security: LiteSpeed Enterprise security advisory – September 14, 2026

Situation We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.   This could allow an attacker to access or alter othe…

Critical
cPanel LiteSpeed

Was das unter einer SharedLicense-Lizenz bedeutet

Your SharedLicense license itself is not affected — this is a change in cPanel, LiteSpeed software, not in licensing. Update the product through its standard update channel; licenses keep working through updates and nothing needs re-issuing or re-activating.

Situation

We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.
This could allow an attacker to access or alter other hosted websites and the server itself.
This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.

Impact

Currently affected versions are LiteSpeed Web Server Enterprise versions prior to v6.3.7.

Call to Action

We strongly recommend upgrading all affected LiteSpeed Enterprise installations to LiteSpeed Web Server Enterprise v6.3.7 or later.
Please run the following command to perform an update to LiteSpeed v6.3.7:

/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen