Skip to finding
important · Privilege — Hosting

An exploited LiteSpeed flaw lets one shared-hosting tenant escape CageFS and reach server-wide root.

Affects

LiteSpeed Web Server Enterprise, the commercial web server commonly deployed on shared cPanel, Plesk and DirectAdmin Linux hosts.

The path starts from a low-privilege hosting account and reaches the privileged lscgid helper; incident response confirmed root access and webshells in other tenants' accounts.

Detail and 2 sources

The exact request sequence is not public, and although fixed builds exist, pre-fix server images remain accepted.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026