rootpwn

medium · CVSS v3 6.7 · CVSS v4 5.4

CVE-2026-104474

OpenLiteSpeed versions prior to 1.9.3 allow local privilege escalation via the lsup.sh script. An attacker who can control the nobody web pr

Overview

OpenLiteSpeed versions prior to 1.9.3 allow local privilege escalation via the lsup.sh script. An attacker who can control the nobody web process can replace an autoupdate package, causing root‑privileged install scripts to run. This flaw enables full system compromise on affected servers.

Description

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.

Impact

Confidentiality: compromised – attacker can read all data. Integrity: compromised – attacker can modify files and configurations. Availability: potentially impacted if attacker disrupts services. The primary audience affected are system administrators and operators of OpenLiteSpeed installations.

Remediation

Apply the official patch to upgrade to OpenLiteSpeed 1.9.3 or later. If an upgrade is not immediately possible, change ownership and permissions of /usr/local/lsws/autoupdate/ to root and restrict write access to nobody. Disable automatic updates or monitor the directory for unauthorized changes. Ensure that only trusted users can execute lsup.sh.

Risk context

The vulnerability has a medium severity (CVSS v3 6.7) and no EPSS data is available, indicating a moderate but not urgent risk. Defenders should prioritize patching or hardening the update mechanism as part of routine maintenance.

Affected products

  • OpenLiteSpeed <1.9.3
  • OpenLiteSpeed 1.8.x
  • OpenLiteSpeed 1.9.0-1.9.2

Scores

Severity
medium
CVSS v2
6
CVSS v3
6.7
CVSS v4
5.4
EPSS
—

privilege-escalation local OpenLiteSpeed webserver update root patch

← All CVEs