important · Privilege — Hosting
An exploited LiteSpeed flaw lets one shared-hosting tenant escape CageFS and reach server-wide root.
Affects
LiteSpeed Web Server Enterprise, the commercial web server commonly deployed on shared cPanel, Plesk and DirectAdmin Linux hosts.
The path starts from a low-privilege hosting account and reaches the privileged lscgid helper; incident response confirmed root access and webshells in other tenants' accounts.
Detail and 2 sources
The exact request sequence is not public, and although fixed builds exist, pre-fix server images remain accepted.