medium · CVSS v3 6.7 · CVSS v4 5.4
CVE-2026-104474
OpenLiteSpeed versions prior to 1.9.3 allow local privilege escalation via the lsup.sh script. An attacker who can control the nobody web pr
Overview
OpenLiteSpeed versions prior to 1.9.3 allow local privilege escalation via the lsup.sh script. An attacker who can control the nobody web process can replace an autoupdate package, causing root‑privileged install scripts to run. This flaw enables full system compromise on affected servers.
Description
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Impact
Confidentiality: compromised – attacker can read all data. Integrity: compromised – attacker can modify files and configurations. Availability: potentially impacted if attacker disrupts services. The primary audience affected are system administrators and operators of OpenLiteSpeed installations.
Remediation
Apply the official patch to upgrade to OpenLiteSpeed 1.9.3 or later. If an upgrade is not immediately possible, change ownership and permissions of /usr/local/lsws/autoupdate/ to root and restrict write access to nobody. Disable automatic updates or monitor the directory for unauthorized changes. Ensure that only trusted users can execute lsup.sh.
Risk context
The vulnerability has a medium severity (CVSS v3 6.7) and no EPSS data is available, indicating a moderate but not urgent risk. Defenders should prioritize patching or hardening the update mechanism as part of routine maintenance.
Affected products
- OpenLiteSpeed <1.9.3
- OpenLiteSpeed 1.8.x
- OpenLiteSpeed 1.9.0-1.9.2
Scores
- Severity
- medium
- CVSS v2
- 6
- CVSS v3
- 6.7
- CVSS v4
- 5.4
- EPSS
- —