FAIL › dossier
cPanel Plugin
PRODUCT· dossier confidence 40%
cPanel is a long-standing web hosting control panel provider with a mixed security posture, recently exposed to high-severity vulnerabilities in its LiteSpeed plugin that allowed privilege escalation and shared hosting isolation bypasses.
PROFILE
CategoryWeb Hosting Management SoftwareWhat they docPanel is a web hosting control panel that provides a graphical interface for managing web hosting accounts, domains, email, databases, and server configurations.Founded1997
Websitehttps://www.cpanel.net ↗
SECURITY POSTURE
cPanel has a mixed security track record, with recent high-severity vulnerabilities in its LiteSpeed plugin exposing privilege escalation and shared hosting isolation bypasses.
Notable failures
- CVE-2026-48172: LiteSpeed plugin RCE via privilege escalation
- CVE-2026-54420: LiteSpeed plugin symlink traversal bypassing shared hosting isolation
Patterns: third-party plugin vulnerabilities; shared hosting isolation bypasses
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-26 | CVE-2026-48172 | high | LiteSpeed cPanel Plugin allows any user to execute arbitrary root scripts via privilege escalation. |
| 2026-06-15 | CVE-2026-54420 | high | LiteSpeed cPanel plugin allows attackers to traverse symlink chains to escape shared hosting isolation on CloudLinux/CageFS. |
DOSSIER SOURCES
- About cPanel: Powering the Web Since 1997 | cPanel · www.cpanel.net
- cPanel - Wikipedia · en.wikipedia.org
Open questions: cPanel's patch response time for CVE-2026-48172 and CVE-2026-54420 · Whether cPanel has implemented additional mitigations for shared hosting isolation bypasses
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:03:44.653137+00:00