CRITICAL: LiteSpeed cPanel Plugin Zero-Day Gives Any Hosting User Root (CVE-2026-48172)
A CVSS 10.0 zero-day in the LiteSpeed User-End cPanel Plugin lets any authenticated cPanel user execute arbitrary scripts as root via the lsws.redisAble JSON-API endpoint. LiteSpeed confirms active in-the-wild exploitation. Plugin versions 2.3 through 2.4.4 are vulnerable, with the fix shipped in 2.4.7.