Many customers' sites run on a single machine, and an attacker with one of those hosting accounts can exploit the flaw to access or alter other sites and the server itself, as per the advisory This article explores security updates litespeed. . CPanel received notice of the flaw, which affects versions prior to 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11.
CageFS is a CloudLinux tool that restricts each hosting account to only view the files within their own directory, preventing them from accessing other accounts or the server's configuration files.
LiteSpeed's announcement of version 6.3.7 described it as a release with "Security improvements, bug fixes, and more!" Its changelog lists three security changes but does not mention a privilege-escalation flaw, and neither company has publicly stated which change resolves it. As of September 15, LiteSpeed's download page still listed 6.3.6 as the stable release, alongside a July pre-release build of 6.4.0 (RC1) whose changelog does not mention the three security updates.
LiteSpeed's update documentation states that forcing a specific version with this command prevents the server from following its stable update cycle, and that administrators can resume automatic stable updates by running touch /usr/local/lsws/autoupdate/follow_stable. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog.











