Security: LiteSpeed Enterprise security advisory – September 14, 2026
Situation We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server. This could allow an attacker to access or alter othe…
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in cPanel, LiteSpeed software, not in licensing. Update the product through its standard update channel; licenses keep working through updates and nothing needs re-issuing or re-activating.
Situation
We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.
This could allow an attacker to access or alter other hosted websites and the server itself.
This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.
Impact
Currently affected versions are LiteSpeed Web Server Enterprise versions prior to v6.3.7.
Call to Action
We strongly recommend upgrading all affected LiteSpeed Enterprise installations to LiteSpeed Web Server Enterprise v6.3.7 or later.
Please run the following command to perform an update to LiteSpeed v6.3.7:
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7
Источники
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему