LiteSpeed Enterprise Bug Allows Root Access from Single Tenant
cPanel warned of a critical privilege escalation vulnerability in LiteSpeed Web Server Enterprise. A user on one site in shared hosting can bypass CageFS isolation and gain root access to the entire server. Versions below 6.3.7 are affected; the patch must be forced via lsup.sh.
- LiteSpeed Enterprise versions below 6.3.7 are vulnerable
- Attack bypasses CageFS isolation and grants root on the server
- No CVE or severity rating assigned yet
- OpenLiteSpeed has not received an update
Read next
Security