CVE-2026-104474
OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
| CWE | CWE-367 |
| Vendor | litespeedtech |
| Product | openlitespeed |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for litespeedtech openlitespeed
Be the first to know when new medium vulnerabilities affecting litespeedtech openlitespeed are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
litespeedtech / openlitespeed
0 < 1.9.3
References
openlitespeed.org: https://openlitespeed.org/release-log/version-1-9-x/ github.com: https://github.com/litespeedtech/openlitespeed/commit/468523ce84388cea9ba6633c26517bc05b3e2bc1 github.com: https://github.com/litespeedtech/openlitespeed/blob/v1.9.2/dist/admin/misc/lsup.sh#L538 vulncheck.com: https://www.vulncheck.com/advisories/openlitespeed-before-1.9.3-local-privilege-escalation-via-lsup-sh-auto-update
Credits
FCI Cloud Security