Skip to content
COOEY

FAIL › dossier

cPanel Plugin

PRODUCT

· dossier confidence 40%

cPanel is a long-standing web hosting control panel provider with a mixed security posture, recently exposed to high-severity vulnerabilities in its LiteSpeed plugin that allowed privilege escalation and shared hosting isolation bypasses.

PROFILE
CategoryWeb Hosting Management SoftwareWhat they docPanel is a web hosting control panel that provides a graphical interface for managing web hosting accounts, domains, email, databases, and server configurations.Founded1997 Websitehttps://www.cpanel.net ↗
SECURITY POSTURE

cPanel has a mixed security track record, with recent high-severity vulnerabilities in its LiteSpeed plugin exposing privilege escalation and shared hosting isolation bypasses.

Notable failures
  • CVE-2026-48172: LiteSpeed plugin RCE via privilege escalation
  • CVE-2026-54420: LiteSpeed plugin symlink traversal bypassing shared hosting isolation
Patterns: third-party plugin vulnerabilities; shared hosting isolation bypasses
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-05-26 CVE-2026-48172 high LiteSpeed cPanel Plugin allows any user to execute arbitrary root scripts via privilege escalation.
2026-06-15 CVE-2026-54420 high LiteSpeed cPanel plugin allows attackers to traverse symlink chains to escape shared hosting isolation on CloudLinux/CageFS.
DOSSIER SOURCES
Open questions: cPanel's patch response time for CVE-2026-48172 and CVE-2026-54420 · Whether cPanel has implemented additional mitigations for shared hosting isolation bypasses
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:03:44.653137+00:00