Breach404
Back to Insights
Secure Software2 min readMay 23, 2026

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A critical vulnerability in the LiteSpeed cPanel plugin allows attackers to execute arbitrary scripts with root-level privileges on affected servers, potentially giving them complete control over hosting infrastructure. Organizations using LiteSpeed with

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free