Skip to content
COOEY

FAIL › dossier

LiteSpeed

VENDOR

· dossier confidence 20%

LiteSpeed is a private technology vendor providing web server and caching solutions with a history of high-severity vulnerabilities in its products affecting millions of sites. Recent failures include privilege escalation and isolation escape flaws in its cPanel plugin, alongside a critical RCE in its caching plugin.

PROFILE
CategoryTechnologyWhat they doLiteSpeed provides web server software, caching plugins, and related technology solutions for hosting and web performance. Websitehttps://www.litespeedtech.com ↗
SECURITY POSTURE

The company has a mixed security track record, with significant vulnerabilities discovered in its web server and caching products affecting millions of sites, alongside recent high-severity privilege escalation and isolation escape flaws in its cPanel plugin.

Notable failures
  • CVE-2024-44000: Unauthenticated RCE in LiteSpeed Cache affecting 6M+ WordPress sites
  • CVE-2026-48172: Privilege escalation allowing arbitrary root script execution in cPanel plugin
  • CVE-2026-54420: Symlink traversal escaping shared hosting isolation in cPanel plugin
Patterns: repeated unpatched edge-device RCEs; privilege escalation in plugin ecosystems; isolation boundary bypasses in shared hosting environments
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-05-26 CVE-2026-48172 high LiteSpeed cPanel Plugin allows any user to execute arbitrary root scripts via privilege escalation.
2026-06-15 CVE-2026-54420 high LiteSpeed cPanel plugin allows attackers to traverse symlink chains to escape shared hosting isolation on CloudLinux/CageFS.
Open questions: founding year and headquarters location · company size and ownership structure · official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:05:14.294871+00:00