OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update. | |
| Title | OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update | |
| First Time appeared |
Litespeedtech
Litespeedtech openlitespeed |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Litespeedtech
Litespeedtech openlitespeed |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T23:28:45.481Z
Reserved: 2026-10-02T00:55:58.387Z
Link: CVE-2026-104474
No data.
Status : Received
Published: 2026-10-03T00:16:35.413
Modified: 2026-10-03T00:16:35.413
Link: CVE-2026-104474
No data.
OpenCVE Enrichment
Updated: 2026-10-03T00:30:19Z
Weaknesses