LiteSpeed's cPanel Plugin: A Symlink Escape and a Root Privilege Escalation, Weeks Apart
Two LiteSpeed cPanel plugin vulnerabilities confirmed exploited in May 2026 form a plausible escalation chain from any tenant account to root on shared hosting infrastructure.