Back to Security Advisories

Security: LiteSpeed plugin automatically removed during nightly update – May 19, 2026

A security vulnerability was found in the plugin provided by LiteSpeed that allowed unauthorized root access to the server.

High
cPanel LiteSpeed

Default Update CMD

sudo /scripts/upcp --force

Situation

A security vulnerability was found in the plugin provided by LiteSpeed that allowed unauthorized root access to the server.

Impact

In order to mitigate this vulnerability further, it is recommended to disable the LiteSpeed User-End Plugin for cPanel. This plugin will be automatically removed as part of the cPanel update on May 19, 2026, for all cPanel versions.

Note: The LiteSpeed web service will continue to function without issue.

Call to Action

The LiteSpeed plugin will be automatically disabled as part of the cPanel update process. Run the following to ensure that cPanel is fully up-to-date: 

# /scripts/upcp –force

To immediately process the plugin removal, the following command should be run:

# /usr/local/lsws/admin/misc/lscmctl cpanelplugin –uninstall

Additional Information

Security: SEC-73728 cPanel & WHM / WP2 Security Update – May 19, 2026

Security: SEC-73755 cPanel & WHM / WP2 Security Update – May 19, 2026

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Check Your System