Key Facts
cPanel warns that a vulnerability in LiteSpeed Web Server Enterprise before 6.3.7 could allow a low-privilege hosting-account user to gain root access on a shared server.
Technical Details
According to cPanel, the issue can bypass controls intended to isolate hosting accounts, including CageFS. LiteSpeed published version 6.3.7 on September 11 with security improvements.
Impact & Mitigation
Administrators running LiteSpeed Enterprise should update to 6.3.7 promptly and verify the deployed version, particularly on shared-hosting systems. cPanel’s advisory does not report public exploitation or provide indicators of compromise.
