boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-48172CRITICAL
LiteSpeed cPanel Plugin
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .1891   97.1   YES
AFFECTED
  Product        Versions     Fixed
  cPanel Plugin  2.3 –        —
  WHM Plugin     unspecified  —
TIMELINE
  May 21  Reserved by mitre
  May 26  Added to CISA KEV, remediation due 2026-05-29
  May 26  Published (CNA: mitre)
  May 30  DUE DATE PASSED — CVE-2026-48172 (LiteSpeed Technologies cPanel Plugin). CISA remediation deadline was May 29, 2026; still in catalog.
  Jul 23  ENRICHED — CVE-2026-48172 (LiteSpeed cPanel Plugin). Received CVSS 10.0 and CPE data from NVD.
CWE-266 · CNA: mitre · CVSS v4.0 · 4 references · NVD status: Analyzed · KEV due May 29, 2026

Description

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
May 21, 2026ReservedReserved by mitre
May 26, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-05-29
May 26, 2026PublishedPublished (CNA: mitre)
May 30, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-48172 (LiteSpeed Technologies cPanel Plugin). CISA remediation deadline was May 29, 2026; still in catalog.
July 23, 2026ENRICHEDENRICHED — CVE-2026-48172 (LiteSpeed cPanel Plugin). Received CVSS 10.0 and CPE data from NVD.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LiteSpeed TechnologiescPanel Plugin2.3
LiteSpeed TechnologiesWHM Plugin

Weaknesses

CWE-266

References (4)

Related

Authoritative record: CVE-2026-48172 at cve.org

Vendors: litespeed technologies

Weaknesses: CWE-266

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-48172 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.