{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-48172",
  "revision": 1,
  "title": "LiteSpeed cPanel plugin — any tenant escalates to root",
  "summary": "The user-facing LiteSpeed cPanel plugin before 2.4.5 mishandles its Redis enable and disable feature, letting any hosting account on the box run code as root and reach every other tenant on the server.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.18914,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-05-26",
    "prerequisites": "Any cPanel account on the shared server."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "LiteSpeed User-End cPanel Plugin 2.4.7"
    ]
  },
  "kill_chain": "privilege_escalation",
  "recommended_action": "Update the LiteSpeed cPanel plugin to 2.4.7 or later now; it has been exploited since May 2026, so grep the cPanel logs for redisAble calls and chase the addresses found.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-48172",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-48172",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-48172",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48172",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/"
    }
  ],
  "published_at": "2026-05-21T02:16:33.760Z",
  "issued_at": "2026-09-24T06:28:59.498Z",
  "tags": [
    "litespeed",
    "cpanel",
    "shared-hosting",
    "privilege-escalation",
    "kev"
  ]
}
